Controllerless Networks

last person joined: 2 days ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

[Ask] IAP (105) Single Login Single Device Solution

This thread has been viewed 0 times
  • 1.  [Ask] IAP (105) Single Login Single Device Solution

    Posted Feb 15, 2014 12:05 PM

    Hi all,

     

    this is my first 'contribution' in Airheads.

     

    Recently, I have PoC and my customer wants to do 'single login on single device only' on IAP environment. Is it possible?

     

    If not, is it possible in any other Aruba envis?

     

    Thank you.



  • 2.  RE: [Ask] IAP (105) Single Login Single Device Solution

    Posted Feb 16, 2014 04:11 AM

    Not too sure you are referring to single single for all application after authentication, if yes check out the latest Clearpass should be 6.4 then it wil lhave single signon for application after you autehnticate via it.



  • 3.  RE: [Ask] IAP (105) Single Login Single Device Solution

    Posted Feb 16, 2014 12:33 PM

    If you are simply referring to the wireless client authenticating then yes............once on the IAP network it will remain authenticated and will have seamless roaming between all IAPs in the network.

     

    Instant APs form a group / cluster.  One of the IAPs behaves in a similar fashion to our controller appliances and it becomes the "Virtual Controller" (VC) and the VC manages the group and is the single point of configuration and monitoring for the group.

     

    If using a pre-shared key it is configured on the VC and all members get this as part of the config.  If using 802.1x the VC becomes the "Authenticator" and is the Radius Proxy that talks to the Radius server.



  • 4.  RE: [Ask] IAP (105) Single Login Single Device Solution

    Posted Feb 16, 2014 10:17 PM

    Hello all,

     

    thank you for replying,

     

    I'm actually referring to this condition:

    Username "A" cannot do logging in twice at the same time. From the perspective of the controller or IAP, I don't want to see this:

     

    Username               ||       OS

    ---------------------------------------------------------------------

    ber23empat                     Android

    ber23empat                     Windows

    ber23empat                     IOS

     

    that's what I meant, and sorry if my explanation is wrongfully misinterpreted.

     

    Thank you again.



  • 5.  RE: [Ask] IAP (105) Single Login Single Device Solution

    Posted Feb 16, 2014 10:32 PM

    From what I know it was not possible on IAP, it is possible to do it on the controller.



  • 6.  RE: [Ask] IAP (105) Single Login Single Device Solution

    Posted Mar 03, 2014 02:11 PM

    depending on the type of network and authentication i believe it might even be tricky on only a controller. with a guest network you can enable single user login. but with dot1x i dont think it is possible without support on the radius server.