Wireless Access

 View Only
  • 1.  Issue using Dynamic VLAN assignment rules

    Posted Mar 22, 2025 08:20 AM

    Hello,

    A little background is that our organization is switching from Meraki APs to Aruba AP-635's running AOS10 managed via Aruba Central. I'm running into an issue with assigning dynamic VLAN rules which I'm hoping some more experienced users can provide some guidance on.

    We have a guest WLAN that is available in all 7 of our buildings. Each building has it's own VLAN ID for the guest network with it's own IP range for each building. I've setup dynamic VLAN assignments rules based on our  AP naming convention which is 'Building Name Room - Asset ID" The rules say if  Access Point name contains "Building Name" assign VLAN ID of the guest network of that building. There's 7 of the rules to cover the 7 buildings.

    Initially this seemed to be working as I connected my iPhone to the guest WLAN and received an IP address in the guest network of the building I was in. The issue appeared when I had a few other devices attempt to connect and they weren't getting an IP address at all. I looked at the clients section in Aruba central and could see that they were trying to connect but that it was trying to assign them VLAN ID's of the other buildings not the actual building they were in even though all devices were connecting to an AP with the proper naming convention of the budling.

    I tried looking up documentation on how Dynamic VLAN assignment rules operate and best practices and really couldn't find anything. Any ideas why it's assigning the correct VLAN for one device but a different one for another device connected to the same AP?

    The only other thing I would like to add that I'm not sure is relevant is that this WLAN has a captive portal that the guest has to acknowledge our network terms before connecting. I like forward to any assistance you can provide me. Thanks



    ------------------------------
    Matt D.
    ------------------------------


  • 2.  RE: Issue using Dynamic VLAN assignment rules

    Posted Mar 23, 2025 02:03 AM

    perhaps you can double check your VLAN assignment rules and ensure the AP names are are all correctly configured. 

    For your testing you can choose the AOS10 group configuration and then use Tools->Commands Tab -> Select your APs 

    and run this "show clients" command, which should display that IP address for the clients and if they are not getting an IP address it will show 0.0.0.0

    This way you can find out if the client is connected to the correct AP or to another



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: Issue using Dynamic VLAN assignment rules

    Posted Mar 23, 2025 05:28 PM
    Edited by bizzy Mar 23, 2025 07:34 PM
    Thank you for the reply. Unfortunately I know they are connected to the right AP because it's the only Aruba AP active in that building because I'm still testing before we do a full rollout. 




  • 4.  RE: Issue using Dynamic VLAN assignment rules

    Posted Mar 24, 2025 04:35 AM

    Hi,

    Have you tested to configure to send the AP name under SSID, Security Settings, Advanced Settings, Called ID Station Type?




  • 5.  RE: Issue using Dynamic VLAN assignment rules

    Posted Mar 24, 2025 10:22 AM

    I have not, as I didn't know this option existed. I will look into it and post my results.




  • 6.  RE: Issue using Dynamic VLAN assignment rules

    Posted Mar 24, 2025 11:43 AM

    Note, if these buildings are situated such that roaming is possible from one building to another, this setup likely won't work.  Roaming requires a common VLAN for the client device.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 7.  RE: Issue using Dynamic VLAN assignment rules

    Posted Mar 24, 2025 03:37 PM

    Thanks for the heads up. These buildings are geographically spread out where that isn't a concern, thankfully.




  • 8.  RE: Issue using Dynamic VLAN assignment rules

    Posted Mar 24, 2025 03:47 PM

    Today I was able to do some further testing and troubleshooting and it appears that the issue is with the fact that the WLAN is setup to use a Captive portal with Aruba's "Cloud Guest". If I change the Security Level from Visitors to Personal removing the Captive Portal I am able to join several devices to that SSID and they get the correct VLAN/IP address from DHCP. Anyone have any ideas on why this would be?




  • 9.  RE: Issue using Dynamic VLAN assignment rules

    Posted Mar 24, 2025 04:04 PM

    Run "show clients debug" on the AP with a client connected via Cloud Guest, the "VLAN" column should have a value in parentheses explaining how the VLAN was derived for that session.  If Cloud Guest is returning a RADIUS VSA then that is going to be applied before any VLAN assignment rules come into play.

    https://arubanetworking.hpe.com/techdocs/aos/aos10/design/vlans/#vlan-assignment-rules



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 10.  RE: Issue using Dynamic VLAN assignment rules

    Posted Mar 25, 2025 10:52 AM

    Thanks for this tip! Running this shows me that the clients connecting to the SSID with the Cloud guest captive portal are getting the default VLAN assigned to them and not a dynamic VLAN from the assignment rules. Using identical rules on an SSID without the captive portal works as intended. It would appear that dynamic VLAN assignment rules don't play well with the Cloud guest captive portal in Aruba central but I cannot find any documentation that confirms or debunks my theory.