Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

RAP with split tunnel ACLs

This thread has been viewed 6 times
  • 1.  RAP with split tunnel ACLs

    Posted Sep 23, 2018 10:12 AM

    Hi,

     

    RAP with split tunnel ACLs and dot1x auth.

    I configured RAP with split tunnel and the traffics are routed just fine.

     

    I checked it by tracert, show datapath session table <client's IP> shows the tunneled traffics alone, Also #show datapath session ap-name <name of the AP> shows the tunneled traffic and not the local traffic.

     

    However, I am unable to see any acl hits when I execute the command #show acl hits and #show acl hits role <default-role>.

     

    When I give the forward mode as tunnel, I see the acl hits but with split-tunnel it doesn't. 

     

    #show acl hits and #show acl hits role <default-role> doesn't show the split-tunnel acls at all. I would like to know why it doesn't show.

     

    Thanks in advance.

     

    Regards,

     

    Sandeep.

     

     



  • 2.  RE: RAP with split tunnel ACLs
    Best Answer

    EMPLOYEE
    Posted Sep 23, 2018 10:31 AM

    When you have a split tunnel ACL, all the traffic is managed by a firewall on the AP.  The "show datapath session ap-name <name of ap> table" should show you everything on the split tunneled ACL.



  • 3.  RE: RAP with split tunnel ACLs

    Posted Sep 23, 2018 10:33 AM

    Thank you colin for that quick response. I see the traffic in "show datapath session ap-name <name of ap> table" but I would like to know why am I unable to see it in show acl hits and show acl hits role <role_name>.



  • 4.  RE: RAP with split tunnel ACLs
    Best Answer

    EMPLOYEE
    Posted Sep 23, 2018 10:56 AM

    Those commands only monitor when the controller's firewall is enforcing the traffic.