Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

what determines the user default VLAN?

This thread has been viewed 2 times
  • 1.  what determines the user default VLAN?

    Posted Jun 05, 2014 07:26 AM

    when i use show user-table ip <ip> i get among the information the following line:

     

    ...

    Vlan default: 80, Assigned: 0, Current: 0 vlan-how: 0

    ...

     

    what determines this Vlan default value? is there a knowledge base article or such?



  • 2.  RE: what determines the user default VLAN?

    EMPLOYEE
    Posted Jun 05, 2014 07:57 AM

    The default VLAN assigned is usually the one in the Virtual AP profile.  There are other factors that can override this like a user or server derived rule or a RADIUS reply with a VLAN attribute



  • 3.  RE: what determines the user default VLAN?

    Posted Jun 05, 2014 08:18 AM

    ok, thank you Seth. i suspected that, but wanted to be sure.

     

    but what when i don't configure a VLAN on the virtual AP profile?



  • 4.  RE: what determines the user default VLAN?

    EMPLOYEE
    Posted Jun 05, 2014 09:22 AM


  • 5.  RE: what determines the user default VLAN?

    Posted Jun 09, 2014 09:49 AM

    thanks very useful link, still wondering about what happens when i dont configure a VLAN on the virtual AP?

     

    actual reason is that i have experienced twice recently on a virtual AP without VLAN configured that it had a Default VLAN in the output and i cant understand where it comes from.



  • 6.  RE: what determines the user default VLAN?
    Best Answer

    EMPLOYEE
    Posted Jun 17, 2014 07:50 AM

    boneyard, Is that vlan 40 the vlan for your controller-ip?  I was in the office and tested by removing the vlan in the VAP and my client got an ip.

     

    The vlan it got the ip was from my controller-ip vlan....either that or it was the first in the list of a 'show ip interface brief'.

     

    You're right though, I should not have gotten an ip address.

     

    Vlan default: 3, Assigned: 0, Current: 3 vlan-how: 0 DP assigned vlan:0

     

     



  • 7.  RE: what determines the user default VLAN?

    Posted Jun 17, 2014 03:13 PM

    vlan 80 you mean i think and yes it was, that could probably be it then. makes a certain sense. still dont get why it suddenly occurs, but i believe best practice would be to set a VLAN on your VAP.



  • 8.  RE: what determines the user default VLAN?

    EMPLOYEE
    Posted Jun 17, 2014 06:46 PM

    Yeah, I meant 80.

     

    I don't think this is right. If there's no vlan on the vap or other vlan derivation, then the device should be without a vlan or 'blackholed'. 

     

    Many years ago in an old VRD, user guide or something I remember it saying that an ap in default group broadcasting Aruba-ap was not a security concern because there was no vlan and the device can't pass traffic.  Clearly somewhere along the line that changed.

     

    Personally, I view that as a bug.



  • 9.  RE: what determines the user default VLAN?

    EMPLOYEE
    Posted Jun 17, 2014 07:18 PM

    @Michael_Clarke wrote:

    Yeah, I meant 80.

     

    I don't think this is right. If there's no vlan on the vap or other vlan derivation, then the device should be without a vlan or 'blackholed'. 

     

    Many years ago in an old VRD, user guide or something I remember it saying that an ap in default group broadcasting Aruba-ap was not a security concern because there was no vlan and the device can't pass traffic.  Clearly somewhere along the line that changed.

     

    Personally, I view that as a bug.


    Michael_Clarke,

     

    I think you should find that old VRD user guide or something so that we can understand what you are talking about.  aruba-ap is no longer configured by default for awhile now.  A Virtual AP without  a VLAN gets the controller's management VLAN.  The VLAN on a Virtual AP is designed to set a default VLAN if needed.  It was not designed as a security measure if the VLAN does not exist.  That is not a bug.

     



  • 10.  RE: what determines the user default VLAN?

    Posted Jun 21, 2014 03:31 PM

    for me it al least explains what happens, thank you both.