I am connecting several buildings on a campus via an Aruba 303-series IAP cluster. Each building is riding on it's own VLAN, connected to each other with trunk ports that also carry a management VLAN.
My goal with the Aruba cluster is to have each building layer-2 segregated, so that when users hop between buildings, they are riding the same SSID, but are getting dropped on the appropriate VLAN for the building.
To solve the dynamic VLAN issue, what I have done is added some sort of description to the name of each AP in each building, suffixing the MAC address. So building 1 might be "ab:cd:ef:00:01-southeast", and building 2 is "ab:cd:ef:00:02-northwest". Then in the dynamic VLAN rules for the SSID, I have one that says "If AP-name contains 'southeast'", it drops them in VLAN X. If it's 'northwest', they get VLAN Y.
This allows me to stick the user on the appropriate VLAN based upon the name of the AP they are hitting (there are multiple APs per building, which is fine since the MAC addresses differ). The buildings are far enough apart that they will never overlap.
My question is: is there a better way to do this in a controllerless setup? From what I understand about zones, those aren't the answer, because then users can't ride the same SSID across each building (each zone has it's own SSID?). I'm curious on if there is a more industry-standard way to do this.