Cloud Managed Networks

 View Only
last person joined: 6 days ago 

Forum to discuss all things related to HPE Aruba Networking Central and UXI Network Management, including deployment of managed networks, configuration, best practices, APIs, Cloud Guest, AIOps, Presence Analytics, and other included Applications
Expand all | Collapse all

remote aps and aruba os 10

This thread has been viewed 41 times
  • 1.  remote aps and aruba os 10

    Posted Jun 28, 2024 11:56 AM

    Hello

    I have Aruba OS 10 with Aruba Central with a foundation WLAN gateway license.

    I need to configure a remote AP like we did on the old version 6.x, The AP will be connected to different sites to give wireless to corporate users.  This will be not a branch office or anything like that, the AP will be taken to different sites constantly 

    I want to know if this remote AP config is now what you call microbranch and does it work with the license I have right? the WLAN Gateway license

    Thanks

    Carlos



  • 2.  RE: remote aps and aruba os 10

    EMPLOYEE
    Posted Jun 28, 2024 08:01 PM

    for microbranch functionality you need the gateways to have SD-WAN foundation or foundation -base 

    here is the Aruba Central SaaS ordering guide



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: remote aps and aruba os 10

    Posted Jul 02, 2024 07:23 AM

    Yeah, Aruba in their wisdom decided to axe remote APs in classic wireless setups, so now you need both an extra dedicated gateway in VPNC/branch mode, and an EXTREMELY expensive central license and complicated redundant WLAN configuration in Central to do what RAP used to do.

    A total fail for Aruba in my opinion. I had a customer that backtracked on their AOS10 Central decision because of the massive cost and configuration overhead this requires.




  • 4.  RE: remote aps and aruba os 10

    EMPLOYEE
    Posted Jul 02, 2024 08:24 PM

    just be aware that you also can have an IAP-VPN solution in which you dont require Aruba Central. All you need is Instant APs at remote sites and an existing controller (non-AOS10 ) 



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 5.  RE: remote aps and aruba os 10

    Posted Jul 03, 2024 11:39 PM

    Hello Ariyap there is no aruba os 8 or anything, all its on aruba os 10 gateways and AP

    They just want to configure ONE ap as a remote AP thats all

    So they need to change their WLAN Gateways subcriptions to SD branch foundation license to have a WLAN infraestructure with gateways like i have it now with the WLAN Gateway license + the microbranch

    The Sd branch will give me both features ariyap? thats what i understand

    Thanks




  • 6.  RE: remote aps and aruba os 10

    Posted Jul 04, 2024 01:46 AM

    Also Ariyap the microbranch i suppose that it can go up the IP with a dchp IP address and do a tunnel when you configure it, so you can take the AP wherever you want, you just need the ipsect port open to establish the VPN tunnel, and as soon as the user connects it, it will just connect automatically to central and start showing the SSIDS

    We just need one SSID with wpa3 enterprise on it for some users that will be moving between different places, it need access to clearpass, but I guess that the only one that need access to that its the gateway not the ap itself 




  • 7.  RE: remote aps and aruba os 10

    EMPLOYEE
    Posted Jul 04, 2024 01:48 AM

    yes thats right



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 8.  RE: remote aps and aruba os 10

    EMPLOYEE
    Posted Jul 04, 2024 02:39 AM

    for configuration example you can refer to technote on microbranch series



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 9.  RE: remote aps and aruba os 10

    Posted Jul 10, 2024 10:47 AM

    Thanks Ariyap 

    Thats a really good technote! 

    Keep doing them please, i see that you have many, they are really helpful! 




  • 10.  RE: remote aps and aruba os 10

    Posted 2 days ago

    Hello Ariyap i saw the technote back when i asked you, but I just got one other question about this

    For the gateway that is the VPNC which is inside the internal network,  with a private IP address 

    I guess its like the remote AP back in the aruba os 6 that I would need to do a virtual IP on the firewall pointing to the private IP of the VPNC gateway right? so I need the firewall admin to do this? this would be virtual IP with the port 4500 udp pointing to the private IP address of the vpnc




  • 11.  RE: remote aps and aruba os 10

    Posted 2 days ago

    When i say virtual ip i mean port forward

    im not sure if other vendor use that name besides fortinet firewall 




  • 12.  RE: remote aps and aruba os 10

    EMPLOYEE
    Posted 2 days ago

    yes thats the way to do it. you need a static 1:1 NAT on your firewall.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 13.  RE: remote aps and aruba os 10

    Posted 2 days ago

    Got it

    thanks!

    I also have this scenario which it seems it's possible as far I see on your aruba central demo page

    on the central site we have 2 controllers with wlan license  with corporate SSID which have their vlan on their network and the DHCP is a windows dhcp one

    we will use another gateway with the sd branch license

    In that gateway, which is on the corporate building we have for example vlan 5, 4

    Let say vlan 5 is the corporate user vlan 

    Can I use that same vlan on the microbranch? I see that I can even pick the gateway and pick the vlan the gateway has.  It will pick the IP of the Windows dhcp in the central site just like the remote AP in version 6.

    It's that possible 

    I'm asking this because, that user network has all the permissions on the firewalls, and it would be good if this is like this.