Controllerless Networks

last person joined: 5 hours ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

Branch office Instant AP problem with VLAN assignment mismatch

This thread has been viewed 1 times
  • 1.  Branch office Instant AP problem with VLAN assignment mismatch

    Posted Jan 04, 2015 03:03 PM

    hi folks,

     

    I get in troubles with my new IAP215 in our new branch office. There is defined an essid "staff" with WPA2-Enterprise security, but RADIUS server is located in our HQ office. Branch is connected with HQ via IPsec tunnel, so IAP215 can reach RADIUS server correctly. There is also essid "staff" in HQ and users are bridged to the VLAN (16,17,18) by the Dynamic VLAN Assignment Rules  according to the value of Aruba-User-Vlan AVP in RADIUS server reply.

     

    Situation in branch office is much more simpler. There are no VLANs, just cable modem, MikroTik router, unmanageable switch and IAP215. The essid "staff" is defined in the same way, but VLAN assignment is set to "Default".

     

    Problem is that user in branch office is not bridged to the LAN and not receive and IP address from MikroTik router. My idea is that IAP is trying to use the value of Aruba-User-Vlan AVP but there are no VLANs to assign to.

     

    Does anybody know how to configure essid to ignore Aruba-User-Vlan value received from RADIUS server ? The essid "test" with WPA2-PSK security works OK.

     

    Thanks.



  • 2.  RE: Branch office Instant AP problem with VLAN assignment mismatch

    EMPLOYEE
    Posted Jan 04, 2015 03:36 PM

    You should send an access-accept to the the remote Instant clusters instead of using the Aruba VSAs. This will likely require a separate service rule / connection requrest policy for your remote offices. 



  • 3.  RE: Branch office Instant AP problem with VLAN assignment mismatch

    Posted Jan 04, 2015 03:41 PM

    So you thing that I should user another type of AVP in RADIUS server responces or filter out this AVP when replied to remote cluster ?

     

     



  • 4.  RE: Branch office Instant AP problem with VLAN assignment mismatch

    EMPLOYEE
    Posted Jan 04, 2015 03:42 PM

    My suggestion would be to create a separate ruleset for branch offices that simply replies back with an access-accept which will put the user in the default VLAN as configured on the Instant cluster.

     

    You can usually use Connection Source IP or NAS-IP as the filter for the connection request(s).



  • 5.  RE: Branch office Instant AP problem with VLAN assignment mismatch

    Posted Jan 04, 2015 04:36 PM

    :) OK, let's see how to do that in the Freeradius.