Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Roaming between controllers

This thread has been viewed 0 times
  • 1.  Roaming between controllers

    Posted Jul 10, 2014 03:05 PM

    Hi:

    I'm in the process of an 802.1x rollout, and I'm having a few problems.

    Users are routinely disconnected when roaming between APs that are on different controllers.

     

    Is there a way to mitigate this?

     

    Thanks,

    Tony

     



  • 2.  RE: Roaming between controllers

    EMPLOYEE
    Posted Jul 10, 2014 03:47 PM

    Normally you would design a network that avoids users roaming between controllers, because their network state is lost when you do that.  If the VLANs the user ends up in on the second controller is different from the first, that is even worse...



  • 3.  RE: Roaming between controllers

    Posted Jul 10, 2014 07:45 PM

    Hi Colin:

    Thanks for the info.

    Right now, it's unavoidable. I've got three 3400 controllers, which only allow 64 AP's each.

    I'm keeping each building on the same controller, but as users roam about campus, they hit different APs and controllers.

     

    I'm planning on getting a 7210, which will host 512 APs.

     

    From what you're saying, it sounds like I should put all my APs on the 7210, and use my 3400's only for backup?

     

    Thanks,

    Tony

     

     


    #7210


  • 4.  RE: Roaming between controllers

    EMPLOYEE
    Posted Jul 10, 2014 08:19 PM

    Well if you have to do that, make sure the virtual APs bridge users to the exact same VLANs:

     

    If your Virtual AP VLAN pool for controller 1 looks like this - 1,5,7 make sure it is 1,5,7 for all of them.  That way your clients will end up in the same VLAN when they roam from controller to controller and they will not have to re-discover their new default gateway or re-ip.  Trunk all of those VLANs to the same layer 3 switch and you should be good to go.