Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Location Discovery for Airgroup

This thread has been viewed 5 times
  • 1.  Location Discovery for Airgroup

    Posted Aug 14, 2014 05:26 PM

    Does anyone know what the rf parameters are for location discovery in Airgroup?  For example what are the rf thresholds that are chosen which decide whether or not a bonjour device is advertised?  Also will this service (right now we are allowing sharing within a specific AP group) be advertised to other AP's not within that specific AP group but within the a reasonably close distance RF wise?

     

     

    Thanks for the info!

     

     



  • 2.  RE: Location Discovery for Airgroup

    EMPLOYEE
    Posted Aug 14, 2014 05:28 PM

    RF parameters are not taken into account. It is simply based on either AP group or the AP itself. If your buildings are very close, you should add in the neighboring buildings as allow locations for the device.



  • 3.  RE: Location Discovery for Airgroup

    Posted Aug 14, 2014 05:33 PM

    Maybe I don't have a fair understanding of what location discovery does.  I was under the impression that it allowed the capability of only advertising devices to users that were within  range of the bonjour servers.  Am I wrong?

     



  • 4.  RE: Location Discovery for Airgroup

    EMPLOYEE
    Posted Aug 14, 2014 05:37 PM
    Yes, but its solely based on the AP-group or the AP name. So you have to be associated to an AP in that group or the AP that is specifically named in order to see the advertised service(s)


  • 5.  RE: Location Discovery for Airgroup

    Posted Aug 14, 2014 05:44 PM

    So then if it is disabled then it is visible to all devices on the Airgroup allowed Vlans.  Correct?



  • 6.  RE: Location Discovery for Airgroup

    EMPLOYEE
    Posted Aug 14, 2014 05:52 PM

    Other AirGroup filters/restrictions would still be in effect (user roles, user groups, and time of day)

     

    If none of those are in place:

     

    • Devices registered as personal will only be seen by the owner.
    • Device registered as shared will be seen by anyone.


  • 7.  RE: Location Discovery for Airgroup

    Posted Aug 14, 2014 08:05 PM

    That information helps alot.  I'm having some issues with a group of Apple TV's that are only shared with one AP group, but are being seen and are available for mirroring  by clients in a completely different AP group.  The AP's are grouped by building and we can walk across the street, associate with an AP in a completely different group and mirror to the devices.



  • 8.  RE: Location Discovery for Airgroup

    EMPLOYEE
    Posted Aug 14, 2014 08:07 PM
    Do you have enforce registration enabled for AirGroup?


  • 9.  RE: Location Discovery for Airgroup

    Posted Aug 14, 2014 08:07 PM

    Yes



  • 10.  RE: Location Discovery for Airgroup

    EMPLOYEE
    Posted Aug 14, 2014 08:19 PM

    Are you seeing the AirGroup authorization messages in Access Tracker in CPPM?

     

    Can you confirm the context information is visible on the controller?

     

    show airgroup cppm entries

     



  • 11.  RE: Location Discovery for Airgroup

    Posted Aug 14, 2014 08:24 PM

    Yes, they show up as entries in the controller, only being shared with the one specific AP group.



  • 12.  RE: Location Discovery for Airgroup

    EMPLOYEE
    Posted Aug 14, 2014 08:26 PM
    OK. I would open a TAC case then.


  • 13.  RE: Location Discovery for Airgroup

    Posted Aug 14, 2014 08:39 PM

    I appreciate the help!

     



  • 14.  RE: Location Discovery for Airgroup

    EMPLOYEE
    Posted Aug 14, 2014 08:41 PM
    Not a problem. Please report back if TAC resolves this issue!