Wireless Access

last person joined: 23 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

APs Dedicated VLAN "not Recommanded" bizard & amazing Info

This thread has been viewed 1 times
  • 1.  APs Dedicated VLAN "not Recommanded" bizard & amazing Info

    Posted May 17, 2015 05:53 PM

    Hi for reference,

    it is not recommended to have an APs dedicated VLAN

    the reason  is below .

     

    AP  VLAN.PNG



  • 2.  RE: APs Dedicated VLAN "not Recommanded" bizard & amazing Info

    Posted May 17, 2015 11:31 PM

    Well, there are other ways to hunt rogues than to have APs out on client VLANs so we feel OK in ignoring that precious gem of "advice."

     

    Why they think 802.1x wired would prevent one from doing so if they wanted to is the most peculiar part of that statement, actually.

     



  • 3.  RE: APs Dedicated VLAN "not Recommanded" bizard & amazing Info

    EMPLOYEE
    Posted May 17, 2015 11:55 PM
    It also just makes a lot of sense from an edge configuration standpoint. There is no technical need/requirement for an AP VLAN.


    Thanks,
    Tim


  • 4.  RE: APs Dedicated VLAN "not Recommanded" bizard & amazing Info

    Posted May 18, 2015 10:13 AM

     

    Sure there is.  Not having to install ACLs on all your switchports to keep clients out of the telnet port when you have to debug the APs, to start with.  Not everyone gets to run on an end-to-end integrated policy framework.

     



  • 5.  RE: APs Dedicated VLAN "not Recommanded" bizard & amazing Info

    EMPLOYEE
    Posted May 18, 2015 10:14 AM
    Disable telnet on the APs?


  • 6.  RE: APs Dedicated VLAN "not Recommanded" bizard & amazing Info

    Posted May 18, 2015 10:19 AM

    >> keep clients out of the telnet port when you have to debug the APs, to start with. 

                                                                   ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

     

    Seriously, though, why would you want your clients to be able to talk directly to APs, ever?  That's just an invitation to trouble.

     

     



  • 7.  RE: APs Dedicated VLAN "not Recommanded" bizard & amazing Info

    EMPLOYEE
    Posted May 18, 2015 10:20 AM
    They're hardened. There's not much you can do to them.


  • 8.  RE: APs Dedicated VLAN "not Recommanded" bizard & amazing Info

    Posted May 18, 2015 10:24 AM

     

    Yeah and fairies live on dandelions.  A properly "hardened" device doesn't support telnet in the first place.  Period.  So I don't think the OP advice is sound.  People should plumb alternate ways to check for rogues if they need to.