Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

7210 controller - separate management plane

This thread has been viewed 9 times
  • 1.  7210 controller - separate management plane

    Posted Aug 18, 2019 08:20 AM
    Hi,

    I have a 7210 controller I want to manage out of band. I have given an interface its own VLAN, and told that VLAN to be management.

    Only issue now is the routing table ... where can I separate the management traffic out? Ideally the management VLAN just gets a default gateway and all other VLANs I will route separately?

    Thanks


  • 2.  RE: 7210 controller - separate management plane

    EMPLOYEE
    Posted Aug 18, 2019 08:54 AM

    The 7210 does have a dedicated management interface.  Please see the installation guide here:  https://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/Command/Core_Download/Default.aspx?EntryId=35393

     

    The interface allows you to enter an ip address and subnet mask.  It is expected that you would have to use a "jump" box on the same subnet to reach the management interface because it cannot route past the management subnet. https://www.arubanetworks.com/techdocs/ArubaOS_85_Web_Help/Content/arubaos-solutions/1cli-commands/interface-mgmt.htm



  • 3.  RE: 7210 controller - separate management plane

    Posted Aug 18, 2019 09:17 AM
    Thanks - but just to be clear, you need to have your management server in the same VLAN? So it never breaks out of the subnet etc?

    I have a bunch of devices in separate out of band subnets - ideally I could tell this management VLAN to use a default gateway on its own routing plane?

    Maybe it is best practice to manage these particular devices in band?


  • 4.  RE: 7210 controller - separate management plane
    Best Answer

    EMPLOYEE
    Posted Aug 18, 2019 09:24 AM

    You can manage (SSH and web) the controller on any ip address on the controller.  

     

    The situation above is ONLY applies to the physical management interface on the 7210.  

     

    From my observation,  the majority of installations just manage the controller on an ip address on one of its vlan interfaces.  The use of the out-of-band management interface is in the minority.