Wireless Access

last person joined: 18 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Oversubscribed un-authenticated users

This thread has been viewed 0 times
  • 1.  Oversubscribed un-authenticated users

    Posted Mar 12, 2012 08:41 PM

    Hi

     

    The issue is this

    We have the Aruba advertising 2 SSIDs. Both of the networks are open, and users connect automatically (they get a private IP), but cannot go anywhere with that IP.

    They are then prompted to authenticate via WPA (Aruba Radius/Ldap) or SSL (on Juniper SA).

    The problem is that alot of the available IPs that an AP can handle are taken up with users devices automatically connecting, but the users dont authenticate. Users who then wish to authenticate are having issues connecting as the APs connection table is full.

     

    Is there a way that with some nominal timeout, that sessions that arent authenticated, are then dropped by the AP, thereby freeing up valuable space for the authenticated users. And thos users that are dropped will then have to reconnect and authenticate should they require access????

     

    Thanks

    G



  • 2.  RE: Oversubscribed un-authenticated users

    EMPLOYEE
    Posted Mar 12, 2012 08:49 PM

    Please see the thread here:  http://community.arubanetworks.com/t5/ArubaOS-and-Mobility-Controllers/Are-Unwanted-Guests-Consuming-Lots-of-IP-Addresses/m-p/26378/highlight/true#M1933

     

    zjennings suggestion is probably one of the best I have heard in awhile.

     



  • 3.  RE: Oversubscribed un-authenticated users

    Posted Mar 12, 2012 09:31 PM

    thanks for that. I did read it.

    Where can I set the lease timeout for these unauthenticated users?

    And would this only affect the unauthenticated users and not the authenticated users?

    Thanks

    G



  • 4.  RE: Oversubscribed un-authenticated users

    EMPLOYEE
    Posted Mar 12, 2012 09:33 PM

    The poster was talking about the DHCP lease.  That would affect both authenticated and non-authenticated users.