Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

External Firewall with Aruba Controller

This thread has been viewed 0 times
  • 1.  External Firewall with Aruba Controller

    Posted Jul 17, 2014 12:53 PM

    Hey all, a bit of a beginning with anything Aruba really.


    So the idea here is to use an external firewall (instead of access control policies) to govern how wireless traffic is handled. 

     

    For example, I set up a SSID on the aruba controller and it needs to only have access to specific services, like dhcp and dns (housed externally as well...not the dhcp server on the controller). How would I go about setting that up so they can work freely together?

    Currently I set up the SSID with a default gateway of the external firewall and set the access control policy to basically allow all so that the controller itself does none of the blocking. Would I, then, set up rules on the external firewall to only allow specific services coming from that network and deny everything else?

    I have already done the rest of the stuff, like setting up a dhcp scope (Externally), setting up the vlan and IP interface on the controller with the correct VLAN information on our switch as well. Also I have put a helper address on the IP Interface information on the aruba controller. 

    Does it sound like I am on the right track, can anyone let me know if this will work properly, etc?

    Thanks!



  • 2.  RE: External Firewall with Aruba Controller

    Posted Jul 17, 2014 01:10 PM

    Hi,

     

    You could setup some firewall policies on your firewall.. You didn't mention what it was and it'll probably be better asking in the  firewall vendors forum about that anyway.

     

    Having said that, I personally wouldn't do it that way. I'd recommend to leverage the capabilities of your controller to enforce the firewall policy. It'll possibly be more secure, you'll be blocking the traffic from hitting the wired network instead of after traversing it and hitting your firewall.

     

    Would you like help setting up firewall policies on your controller? :)

     

    Cheers

    James