Please check this post I made earlier today. Disable local-routing in order to force all traffic through your firewall; it may also solve the problem that the management interface is accessible from other networks. Please let us know the results after you tried.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: May 08, 2025 02:39 AM
From: Amadeusz
Subject: Aruba AP315, problem to login to conductor
Hi
I created a rule from this thread: "Allow app https to AP IP all", in order to access the GUI while connected to the Wi-Fi network. Access to the controller works correctly, as does internet access. Unfortunately, the controller is also accessible from other Wi-Fi networks, not just the one I intended. Another issue is that traffic to the controller no longer passes through the firewall (I have a Palo Alto at the network edge); instead, it seems to be handled locally by the access point, which means I have no control over this traffic.
Original Message:
Sent: May 07, 2025 02:31 AM
From: Kevin Rice
Subject: Aruba AP315, problem to login to conductor
I even wrote here about it:
https://community.arubanetworks.com/discussion/iap-325-gui-unreachable-via-wi-fi-side-but-wi-fi-internet-access-works
Original Message:
Sent: Apr 19, 2025 03:41 AM
From: mozajo
Subject: Aruba AP315, problem to login to conductor
Hi,
I have three Aruba AP-315 access points running in the same subnet. One of them acts as the conductor, and I manage the entire setup from there. Here's the setup:
- AP1 – 10.11.1.42 (conductor)
- AP2 – 10.11.1.43
- AP3 – 10.11.1.44
The issue is that when I'm connected to the WiFi network provided by these APs, I can only access the web interface of AP2 and AP3. I cannot log in to AP1 (the conductor) via WiFi - the management page doesn't load. It only works when I connect my computer using a wired connection.
It's definitely not a firewall issue - all APs are in the same subnet and VLAN. Two are accessible, one isn't. Could this be some sort of built-in security feature on the conductor that blocks management access over WiFi? If so, how can I disable or reconfigure it?