What is Domain Pre-connect in VIA and how does it work?

Aruba Employee
Aruba Employee
Question What is Domain Pre-connect in VIA and how does it work?
Environment Only Windows Platform Supports this Feature



VIA 2.1 contains a new feature of Domain Pre-Connect. 

"Domain Pre-Connect", which is intended to let a client machine establish a connection to the controller even when the user is not logged in.  This lets the machine be in contact with a domain controller, which can be handy for password changes/expiration. 
The support starts from AOS or later on the controller to take advantage of all the latest features, although VIA 2.1 is backwards compatible with previous versions if you do not need the new features.

Domain Pre-Connect allows the VIA client to start when the computer is at the ctrl-alt-delete screen and submit machine credentials in the background.  The machine would of course have to be wired, or connected to a wifi network that would allow it to pass IPSEC traffic at the ctrl-alt-delete prompt.
You would have to already have downloaded and installed the VIA client and above and connected once using a VIA connection profile that has the "domain pre-connect" checkbox enabled.  This checkbox is only available in ArubaOs and above and is located in the VIA Connection Profile:

The idea of this feature is to connect you to the enterprise network as if you have the ethernet cable plugged in, but over VPN.  That will allow you to do things like run login scripts, and be able to change an expiring password at the ctrl-alt delete screen.

Make sure you have network connectivity to the client when user is logged off.
·         Configure VIA connection profile for IKEv2+User certificates. (The feature works only with IKEv2 as of now).
·         The certificates have to be stored in machine store.
·         Establish at least one normal VIA IPsec connection when user is logged into the machine. (domain pre-connect creates its own profile using this profile).
·         Now log off the machine domain pre-connect would be initiated.
·         In controller you can see, the initial IPsec connection will be teared off and new connection will be triggered. (Use “show user” command).
Configuration from CLI
aaa authentication via connection-profile "via_conn_prof"
Configuration from WEBUI
Go to Configuration tab--> Security--> Authentication-->L3 Authentication -->Click on VIA connection Profile


Version history
Revision #:
1 of 1
Last update:
‎07-10-2014 04:05 PM
Labels (2)

Configure VIA connection profile for IKEv2+User certificates


Does domain pre-connect work with the EAP-TLS method?

Search Airheads
Showing results for 
Search instead for 
Did you mean: