Cloud Managed Networks

 View Only
  • 1.  Assign Dynamic VLAN based on Device Category

    Posted Oct 29, 2024 07:19 AM

    Hi all,

    I am trying to make my SSID push smartdevices to a seperate vlan with wifi.

    Ik found the Dynamic VLAN options, but I cant find the option to select device type as a value.

    This 1 one of the devices

    As you can see, central puts it in "category" "smartdevice"

    But i an not sure what the right option is under the Dynamic VLAN assignment to use this value as a reference

    I hope anyone here has the answer ;)

    Kind regards,

    Wouter



  • 2.  RE: Assign Dynamic VLAN based on Device Category

    Posted Oct 29, 2024 08:59 AM

    You can do this with Cloud Authentication and Policy, which is under the Global View, then Security and Authentication and policy. There you can create device policies that point assign a role depending on the client tag ([Mobile & Gadgets]). When you have done that, use Cloud Auth as authentication server for your network.

    The VLAN assignment roles are AP 'local significant', so that doesn't have access to the profiling information in Central unless you link it through Cloud Auth (or ClearPass).



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Assign Dynamic VLAN based on Device Category

    Posted Oct 29, 2024 09:17 AM

    Hi Herman,

    I created a new Role "xxx_IOT" and allowed all traffic and assigned VLAN20.

    I then did as u suggested and created the policy.

    The WLAN itself uses PSK to authenticate, but i only see CloudAuth under Enterprise.

    Am i missng something?




  • 4.  RE: Assign Dynamic VLAN based on Device Category

    Posted Oct 29, 2024 09:20 AM

    I think i found it.

    Enable Mac-Auth and then enable Cloudauth




  • 5.  RE: Assign Dynamic VLAN based on Device Category

    Posted Oct 29, 2024 09:23 AM

    Is this also possible for switches to assing VLAN based on DeviceType?




  • 6.  RE: Assign Dynamic VLAN based on Device Category

    Posted Oct 29, 2024 06:00 PM

    yes you can also enable MAC auth and choose CloudAuth for it.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 7.  RE: Assign Dynamic VLAN based on Device Category

    Posted Oct 30, 2024 03:44 AM

    Good to know, but how?  i found options using the GUI way, but not for template configured switches.