Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

AirGroup Question

This thread has been viewed 4 times
  • 1.  AirGroup Question

    Posted Dec 14, 2012 06:48 AM

    We are trying to master the use of Airgroup on the controller and it seems like there isn't a whole ton of options. However, I was wondering if anybody has figured out (Without Clearpass) how to limit the list that gets brought up on the IPad.  I don't want to get as granual as per person but I was thinking more like per ap group or per vlan or something like that.  Has anybody done anything like this?  Is it even possible?



  • 2.  RE: AirGroup Question

    EMPLOYEE
    Posted Dec 14, 2012 06:56 AM

    You can block services via role:

     

    config t
    airgroupservice airplay
    disallow-role Students

     

     

    That will block anyone in the Students role from seeing any Airplay devices.

     

     



  • 3.  RE: AirGroup Question

    Posted Dec 14, 2012 11:38 AM

    Can it be done per VLAN rather than per role?

     

    It would be nice to limit users to seeing Airplay devices in their building.

     

    Thanks,

     

    Brad



  • 4.  RE: AirGroup Question

    EMPLOYEE
    Posted Dec 14, 2012 01:44 PM

    There is an option for that.

     



  • 5.  RE: AirGroup Question

    Posted Dec 14, 2012 04:27 PM

    To disallow a VLAN:

    airgroupservice airplay

       disallow-vlan <id>

     

    To cofirm:

    show airgroupservice

    show airgroup vlan

     



  • 6.  RE: AirGroup Question

    Posted Dec 15, 2012 04:32 AM

    I'm not looking to disallow AirGroup, I'm looking to isolate it by building.

     

    Brad



  • 7.  RE: AirGroup Question

    Posted Dec 15, 2012 09:41 AM

    Sorry, thought you asked how to do it by VLAN?  How are you differentiating your buildings?  Roles?  VLANs?   AP Groups?



  • 8.  RE: AirGroup Question

    Posted Dec 17, 2012 09:20 PM

    It would be nice if you can do it per Ap-group land vlan. However, if somehow we can't figure out how to do it with one of them that would work.

     

    Example would be-

     

    ipad connects to ap group ms. It sees list apple devices only in the ms ap group and/or certain vlan. 

     

    Then ipad connects to app in HS group and that iPad only sees ones in the Hs ap group and/or a certain vlan. 

     

    Make sense?



  • 9.  RE: AirGroup Question

    EMPLOYEE
    Posted Dec 18, 2012 05:33 AM
    John,

    It does make sense. Please post to the ideas portal.

    Quick question, how are you using it today.


  • 10.  RE: AirGroup Question

    Posted Dec 20, 2012 02:16 PM

    i believe this is already possible with an airgroup intergrated setup, you can do something with the AP group and vlan if im not mistaken.



  • 11.  RE: AirGroup Question

    Posted Mar 05, 2013 02:50 PM

    I am trying to deploy an almost identical Airgroup scenario.

    I have roughly 150 schools, each of which has a unique AP-Group and vlan pool.

     

    We would like to be able to enable AirPlay but we need to keep the visable devices in each school limited only to those which are in the same vlan pool.  In other words keep the iPad in school "A" from playing to the AppleTV in school "B"  Is there a way to accomplish this without the benefits of having Clearpass?

     

    I should point out that I was planning on using an overlay controller in my test deployment.

     

    Thanks in advance.

     

     



  • 12.  RE: AirGroup Question

    EMPLOYEE
    Posted Mar 05, 2013 11:01 PM

    Why don't you just block the bonjour protocol at the border of each school using your layer-3 switch?  If you have not built it yet, it looks like you have to schedule a design session with your Aruba SE to determine the best way to do what you require.  There are potentially alot of moving parts in what you are proposing.

     



  • 13.  RE: AirGroup Question

    Posted Mar 06, 2013 12:12 PM

    You may be onto something there. Something I had not considered.

    You are correct about the large number of moving parts, but all of my user VLANs are terminated back here at the data centre and all on the same core switch.

    I will have to discuss the possibility of blocking Bonjour on a per site basis with my collegue at the next desk.

     

    Thanks for the ah-ha! moment.

     

    /Terry

     

     



  • 14.  RE: AirGroup Question

    Posted Aug 29, 2013 09:34 AM

    Have you found a solution for this yet?

     

    We are a school district running into the same issue.

     

    We terminate all the AP's back at the data center.  We have Vlan Pools setup for each school.  Right now, all the schools can see each others ATV's.  Is there a way to limit this from the controller?

     

    edit - I've created a new thread on this.



  • 15.  RE: AirGroup Question

    Posted Sep 27, 2013 12:07 PM

    Any update on this for 6.3.0.1?

     

    Would be nice if there is an idea on how to limit bonjour per building or AP group without ClearPass.

     

    Thanks