Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Can Aruba support 2 wlans using two different radius servers

This thread has been viewed 0 times
  • 1.  Can Aruba support 2 wlans using two different radius servers

    Posted Aug 18, 2015 07:43 PM

    Does Aruba support per SSID radius authentication? If so, please explain the configuration behind the following.

     

    ssid a authenticates against radius server a

    ssid b authenticates against radius server b

     

    Lastly, what are the default aaa timeouts and can they be adjusted?



  • 2.  RE: Can Aruba support 2 wlans using two different radius servers
    Best Answer

    EMPLOYEE
    Posted Aug 18, 2015 07:46 PM

    1.  yes.  When you create a wireless network with the wizard, you are asked what radius server you want to point it to.

    2.  When you say default AAA timeouts, what do you mean?

     

     



  • 3.  RE: Can Aruba support 2 wlans using two different radius servers

    Posted Aug 18, 2015 08:05 PM
    What are the default timeouts for authentication? For instance, I have a high latency link that I want to authenticate over..

    Bill Dugas


  • 4.  RE: Can Aruba support 2 wlans using two different radius servers

    EMPLOYEE
    Posted Aug 18, 2015 08:10 PM

    The 802.1x timeout is typically 2 seconds.  Many 802.1x clients themselves give up after 100 miliseconds.

     



  • 5.  RE: Can Aruba support 2 wlans using two different radius servers

    MVP
    Posted Aug 19, 2015 06:01 AM
      |   view attached

    See the attached .pdf to get a better understanding of how different profiles are combined to result in the network configuration.

    Since a network config is tied into a virtual-ap profile which can include different SSID and aaa profiles the short answer to your question is: Yes, Aruba supports per SSID authenticatio.

     

     

    disclaimer: That .pdf is from an antiquated version (3.0) but the logic hasn't realy changed since so still current to get a basic understanding. It certainly does NOT include all the possible profiles !

    Attachment(s)

    pdf
    3dot0-profiles-v2a.pdf   19 KB 1 version