Wireless Access

last person joined: 10 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

single ssid with multiple vlans using mac address

This thread has been viewed 4 times
  • 1.  single ssid with multiple vlans using mac address

    Posted Aug 23, 2017 05:55 AM

    how do I implement single ssid with multiple vlans with mac address authentication?

     

    Any step by step guide available?



  • 2.  RE: single ssid with multiple vlans using mac address

    EMPLOYEE
    Posted Aug 23, 2017 08:19 AM

    Is this an Aruba Controller or instant?  Are you already doing mac authentication on a single vlan?



  • 3.  RE: single ssid with multiple vlans using mac address

    Posted Aug 23, 2017 08:22 AM

    It will be a controller based deployment..



  • 4.  RE: single ssid with multiple vlans using mac address
    Best Answer

    EMPLOYEE
    Posted Aug 23, 2017 08:25 AM

    You should break your problem into two parts.  Mac authentication is something that you add to an open or a preshared key network.  Have you set those up yet?  After that you add mac authentication:  http://community.arubanetworks.com/t5/Community-Tribal-Knowledge-Base/For-the-Beginner-MAC-Authentication-using-the-Controller/ta-p/32188

     

    By the way, mac authentication does not scale.  Adding/removing and managing mac addresses adds alot of administrative overhead.



  • 5.  RE: single ssid with multiple vlans using mac address

    Posted Aug 23, 2017 08:31 AM

    I actually had configured in this way and it worked for 2 days. Issue came when we wanted to have a captivate portal for guest login. 

    As per captivate portal requirement, need to have a interface ip from the same vlan where clients will be connecting.

     

    We ran in to problem and had to reset the entire configuration. Unfortunately, TAC couldn't fix it. Client was unable to get the ip from dhcp.

     

    At this moment, when I have reset the controller and reconfigured it. Everything is working again. Just wanted to confirm if my approach is correct or no. Would need assistance with captivate portal configuration though..

     

    Thanks a ton...



  • 6.  RE: single ssid with multiple vlans using mac address

    EMPLOYEE
    Posted Aug 23, 2017 08:35 AM

    You need tri-session with DNAT enabled if you want to do captive portal on more than one VLAN:  http://community.arubanetworks.com/t5/Wireless-Access/Tri-Session-with-DNAT-vs-Controller-IP-Address-on-Client-VLAN/m-p/280237

     

    If you want to add more than one VLAN, typically you would use VLAN pooling (put more than one VLAN in the Virtual AP VLAN).