Wireless Access

last person joined: 19 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

MASTER/LOCAL VS BRIDGE-MODE RAP - for authentication

This thread has been viewed 0 times
  • 1.  MASTER/LOCAL VS BRIDGE-MODE RAP - for authentication

    Posted Sep 07, 2012 01:24 PM

    Hi Guys,

     

    Understand MASTER/LOCAL is for redundancy, but from authentication aspect, can I have Local APs connecting to Local Controller to authenticate user to a Local RADIUS?

     

    For Bridge mode RAP, if I specify authentication server pointing to a local Radius server, will the authentication be going back to the controller and back to the local site again, since the controller is the Radius Client to the radius server?

     

    Having said that, for a deployment without redundancy, I can have multiple remote site with RAP to a single Controller at HQ all running bridge mode?

     

    Appreciate if anyone can help =)

     

    Cheers!

     



  • 2.  RE: MASTER/LOCAL VS BRIDGE-MODE RAP - for authentication

    Posted Sep 07, 2012 02:50 PM

    Hi Hoopsanity,

     

    You should think of master local as a management model more than redundancy. You might want to take a look at the controller VRD. 

     

    In your model, you're talking about authentication using an authenticaiton server on the local site correct? Authentication from the controller would have to go back to the local site, and you'd likely want to have a site-to-site VPN for that to happen. If you want bridged traffic with local authentication you're likely better off using Aruba Instant AP at the site.

     

    thanks,

    -awl



  • 3.  RE: MASTER/LOCAL VS BRIDGE-MODE RAP - for authentication

    Posted Sep 10, 2012 02:17 AM

    Hi Andy, Thanks for the response, appreciate it =)

     

    With the Master/Local deployment can i assign remote site AP to do authentication with the remote site Radius Server instead of letting the authentication traffic going back to the Master Controller located at the HQ and back to the Remote Site.

     

    Sorry if the question sounds silly, as I assume the Master Controller is the Radius Client of the Remote Site Radius as the configuration held there.

     

    Thank you!