Wireless Access

Reply
New Contributor
Posts: 2
Registered: ‎01-30-2017

Change forward mode/tunnel data traffic based on RADIUS attribute

[ Edited ]

Dear all

 

One of our customers has got the following setup:

 

  • WLAN controller located in the datacenter (OS v. 6.3.1.15)
  • APs located at different branch offices
  • APs wired to switch, no VLAN trunking
  • One SSID for private WLAN data traffic (auth mode = PEAP)
  • WLAN data traffic is locally switched (forward mode = bridge)

I would like to know if there is way to dynamically instruct the APs to tunnel WLAN traffic back to the controller based on a RADIUS attribute.

 

I noticed that if the default forward mode for the SSID is set to tunnel (within the Virtual AP basic configuration), I'm able to bridge the traffic locally by useing the RADIUS Server which sends back the native VLAN number as VSA attribute after authentication.

 

My question now is: Can this be done when the default forward mode is set to bridge? Can I override this configuration with a RADIUS attribute and tunnel the data traffic back to the controller?

 

Any help or brief instructions would be much appreciated.

 

Best regards,
Matt

Highlighted
Aruba
Posts: 1,287
Registered: ‎08-29-2007

Re: Change forward mode/tunnel data traffic based on RADIUS attribute

This is possible if the APs are RAPs and the mode is split-tunnel.

 

You can set different roles based on this attribute.

 

If you want traffic to tunnel back to the controller, then it would be a 'permit' rule in the acl.  For traffic to break out locally, it would be a 'route src-nat' rule in the acl.

 


If my post is helpful please give kudos, or mark as solved if it answers your post.

ACCP, ACMP, ACMX #294
mclarke@arubanetworks.com
New Contributor
Posts: 2
Registered: ‎01-30-2017

Re: Change forward mode/tunnel data traffic based on RADIUS attribute

Hi Michael 

 

Thanks for the quick response, I will dig deeper into the split-tunneling setup.

 

Regards,

Matt

Occasional Contributor II
Posts: 11
Registered: ‎05-08-2015

Re: Change forward mode/tunnel data traffic based on RADIUS attribute

The split tunnel is the possible solution, but remember that the AP will NAT all trafic not tunneled using its local IP if you do. The clients wont be handled by the local network the same way as when using bridged mode on the SSID.

Search Airheads
Showing results for 
Search instead for 
Did you mean: