Hello,
I am uncertain on how to respond to the quote given below.
A big motivation for putting APs in existing VLANs seems to be for Aruba rogue detection, however Airwave is good at detecting wireless detection and does not have that restriction. Airwave scans switches for matching arp data and puts the wired and wireless data together for an overall picture. Why is the author of this document so insistent? Is this old advice?
Also, advising APs be placed on existing VLANs may raise certain alarms with security people. Yes, I know, the user traffic is tunneled back to the controller so you could argue about how much of a risk this really is. There is an advantage in only enabling certain switch ports and knowing legitimate APs are in a limited number of IP addresses ranges. This makes things easier to track.
Regards,
David
From Aruba Mobility Controller VRD
"AP VLANs:
Aruba strongly recommends that edge access VLANs should not be dedicated to
APs except in environments where 802.1X is a requirement on the wired edge. The APs should
use the existing edge VLANs as long as they have the ability to reach the mobility controller.
Deploying the APs in the existing VLANs allows for the full use of the Aruba rogue detection
capabilities."