Wireless Access

last person joined: 23 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Barracuda & Aruba

This thread has been viewed 0 times
  • 1.  Barracuda & Aruba

    Posted Dec 06, 2012 08:15 PM

    We currently have an inline Barracuda content filter on our network. It is the Second to last step out on the network, afterwards comes the firewall, then the WAN.

     

    We monitor all web traffic through the Barracuda filter, however we have an issue tracking user on the guest network (which is in a different subnet than the rest of our network). It currently only logs the Aruba Main Controller IP address.  What do we have to do to get it to pass the guests IP through?  The Guest's IP will be in a 10.99.1.0/24 range, while our main network is 10.1.0.0/16.

     

    Also to include: 

    We run ArubaOS 6.1.3.1 on an Aruba 3600

     

    Thanks!

    ArubaOS 6.1.3.1


    #3600


  • 2.  RE: Barracuda & Aruba

    Posted Dec 06, 2012 10:15 PM

    Hi,

     

    Are you NAT'ing the Guest IPs on the controller, or on your firewall that is outside the Barracuda filter?



  • 3.  RE: Barracuda & Aruba

    Posted Dec 07, 2012 05:06 AM
    Not sure haha. There are a lot of settings in Aruba. I thing they are Nat'd on the controller.


  • 4.  RE: Barracuda & Aruba

    EMPLOYEE
    Posted Dec 07, 2012 05:44 AM

    Check on the VLAN interface to see if "source nat" is enabled.

     



  • 5.  RE: Barracuda & Aruba

    Posted Dec 07, 2012 06:29 AM

    Source NAT is enabled on the VLAN.  Here is a print of the page.

     ss.png



  • 6.  RE: Barracuda & Aruba

    EMPLOYEE
    Posted Dec 07, 2012 06:31 AM

    Okay.  You have to remove the NAT, but make that guest subnet fully routable in your network.  There must be a route internally, pointing to the controller's management interface for that subnet.  Your firewall at the perimeter also must also have a route to the controller for that subnet and be able to nat the traffic out.