I’ve read about hierarchical deployment in the Aruba Instant Validated Reference Design - V2.0, this is something I’ve personally not seen in the wild.
This got me thinking on how this could apply to using the IAP as a CPE.
I could not find any recent examples; here is the older one https://community.arubanetworks.com/t5/Controller-less-WLANs/How-to-configure-and-troubleshoot-a-hierarchical-deployment/ta-p/179760
I’ve configured the Hierarchical deployment in my lab using Aruba Instant OS 8.3.0.6.
AP-203R eth 0 connected to the internet and eth1 connected to port 1 on the 2530.
The 2530 connects to other IAPs (315 on port 8) and wired clients.
![H IAP.jpg H IAP.jpg](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_56ac00c7c0874be285a87c803c93afea)
I’ve kept the switch configuration basic
![Screen Shot 2019-03-21 at 3.47.10 PM.png Screen Shot 2019-03-21 at 3.47.10 PM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_f1aba1ef0aa548bd979da4681219f778)
Log into Instant WebUI
Click on "Wired" from the Main menu in the top-right corner.
Click on "New" to create Wired Ethernet Profile:
![Screen Shot 2019-03-21 at 10.47.46 AM.png Screen Shot 2019-03-21 at 10.47.46 AM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_01b0dc71858f4d84b3196c285840aae2)
Configure Wired Settings for downlink to the LAN switch.
![Screen Shot 2019-03-21 at 10.49.38 AM.png Screen Shot 2019-03-21 at 10.49.38 AM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_f3bb3924a4d744debef2ac3fa09bc689)
Under VLAN Management, configure Port mode (Trunk). Add allowed VLANs for Eth1, in my case I used; 101 (IAP), 102 (Switch), 201 (Employee) and 202 (Guest). Note the native VLAN is not specified, we will come back to this later.
I did not set any L2 Security on this downlink port, I did not want to complicate adding other Access Points to the cluster in my test lab.
I did not set any policy, everything is allowed on the downlink port.
![Screen Shot 2019-03-21 at 10.53.37 AM.png Screen Shot 2019-03-21 at 10.53.37 AM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_4b23dcc8399746799631147f01cd82fb)
After finishing the wired profile, I assigned it to eth1 on the 203R
![Screen Shot 2019-03-21 at 10.54.31 AM.png Screen Shot 2019-03-21 at 10.54.31 AM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_5140c48362b24784a94a754c2efe36ee)
I used Local DHCP Scopes on the IAP for the VLANs setup in the Wired Ethernet Profile.
Note the VLAN IDs in the scope should match the VLAN IDs in the Wired Ethernet Profile.
![Screen Shot 2019-03-21 at 10.57.43 AM.png Screen Shot 2019-03-21 at 10.57.43 AM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_dd7e8cbad79f471abf7c13ee3178aa07)
IAP Private VLAN for other Instant Access Points to form the IAP Cluster
![Screen Shot 2019-03-21 at 11.10.56 AM.png Screen Shot 2019-03-21 at 11.10.56 AM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_c9e2d4c99c6047dea3ebdf181f970ed3)
Infra for managing local site infrastructure like the switch.
![Screen Shot 2019-03-21 at 11.12.05 AM.png Screen Shot 2019-03-21 at 11.12.05 AM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_d9cbf95f5eb84e22b52678ce231c10cc)
Employee, I used this scope for both wired and wireless client end devices.
![Screen Shot 2019-03-21 at 11.16.18 AM.png Screen Shot 2019-03-21 at 11.16.18 AM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_542391c02298495a8cb8ff47568f7e16)
Last the Guest scope
![Screen Shot 2019-03-21 at 11.17.24 AM.png Screen Shot 2019-03-21 at 11.17.24 AM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_6aca0e8e447d437a9f00af43b628976d)
At this point I went back to edit my Wired Downlink Profile, remember we had no untagged/native VLAN set on the IAP and the switch is expecting IAP Private VLAN 101 as untagged/native. This bit is not obvious, but “Client VLAN assignment” sets the untagged/native VLAN.
![Screen Shot 2019-03-21 at 3.31.52 PM.png Screen Shot 2019-03-21 at 3.31.52 PM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_34907b4a4f234d7ab522f21de181904b)
My LAN switch was now getting an IP address from DHCP on the 203R IAP
![Screen Shot 2019-03-21 at 3.48.15 PM.png Screen Shot 2019-03-21 at 3.48.15 PM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_2472e592713c49259cde2ef143400080)
The 315 joined the cluster
![Screen Shot 2019-03-21 at 3.30.52 PM.png Screen Shot 2019-03-21 at 3.30.52 PM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_11ad9ee81b424704b3a41edb4c9c924e)
I configured a basic employee WLAN Network
I used the same VLAN 201 for the wireless and wired devices
I set a basic PSK
![Screen Shot 2019-03-21 at 12.41.12 PM.png Screen Shot 2019-03-21 at 12.41.12 PM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_77a836e58fcd49cc9a60b42813555915)
I used the same open allow all access as wired
![Screen Shot 2019-03-21 at 12.41.40 PM.png Screen Shot 2019-03-21 at 12.41.40 PM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_470ecedadd3048d6a1faf97c12050a5f)
Lastly, I connected Clients.
Tinkerbell plugged into the 2530 and a wireless client on each Access Point.
![Screen Shot 2019-03-21 at 3.54.29 PM.png Screen Shot 2019-03-21 at 3.54.29 PM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_0944b560b8fe403fbe8e05094aa4b80a)
![Screen Shot 2019-03-21 at 3.53.52 PM.png Screen Shot 2019-03-21 at 3.53.52 PM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_a07354a03a6c4147b8172c7499a77d85)
![Screen Shot 2019-03-21 at 4.26.09 PM.png Screen Shot 2019-03-21 at 4.26.09 PM.png](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_97663e72a44445c9a72ef260e7e8884c)
I even managed to get decent speeds, my UFB is limited to 100Mbps down and 20Mbps up.
![speed.jpg speed.jpg](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_f7b0fbeb56ba409d8d0b4f59e45a297f)
Note the uplink on the 203R is ethernet with DHCP provided, standard UFB / NBN stuff in ANZ.
Some ISPs in NZ require you to add an 802.1q VLAN tag on the uplink.
![vlan10.jpg vlan10.jpg](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/22bb0ce66404440081e135d6585d9b7c_c126713a00f146218e613dea0d8896e4)
You may even want to use 4G as backup
https://community.arubanetworks.com/t5/Education-Australia-New-Zealand/IAP-4G-Modem-Configuration/gpm-p/296720