Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Can you create custom AirGroup Services for custom ports?

This thread has been viewed 3 times
  • 1.  Can you create custom AirGroup Services for custom ports?

    Posted May 07, 2018 05:18 PM

    I'm trying to set up AirGroups for a custom multicast service that isn't part of the pre-canned AirGroups services on AOS. I was wondering about the following:

     

    - Is there a list of all Service ID's you can use?

    - Is there a way to create a custom service with the required TCP/UDP ports?

     

    Thank you!



  • 2.  RE: Can you create custom AirGroup Services for custom ports?

    EMPLOYEE
    Posted May 07, 2018 05:30 PM

    You can define any valid mDNS or SSDP service string. Ports are not used.



  • 3.  RE: Can you create custom AirGroup Services for custom ports?

    EMPLOYEE
    Posted May 07, 2018 05:34 PM

    Airgroup is not specifically for multicast.  It is for services that advertise their services via multicast DLNA or MDNS.    Please see here: http://www.arubanetworks.com/techdocs/Troubleshooting/ArubaOS/AirGroup_Troubleshooting/Web_Help_Index.htm#arubaframestyles/troubleshooting%20topics/airgroup.htm%3FTocPath%3D_____2 if you have a DLNA or MDNS device that is not showing up.



  • 4.  RE: Can you create custom AirGroup Services for custom ports?

    Posted May 09, 2018 03:52 PM

    Thank you for the information. The reason why I am inquring is because I am trying to utilize airgroups to allow isolation of devices on a per user basis using CPPM. Hwoever there is a limitation to AirGroups since the custom protocol I need is not available on there.

     

    Another method I was thinking would work is if there is a way to completely isolate devices that users register on the Clearpass Guest Portal. Ideally, a user will register the mac-address of their devices, and once connected to the network, only have access to the Internet and the other devices that they registered.

     

    Is this something that can be done with the "Deny Inter-User" configuration?



  • 5.  RE: Can you create custom AirGroup Services for custom ports?

    EMPLOYEE
    Posted May 09, 2018 04:26 PM

    AirGroup is not a security feature. It ONLY controls mDNS and SSDP advertisement. It does not control/restrict/enforce any other part of the datapath.