Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Access Rules IAP 103 - Proper configuration method

This thread has been viewed 3 times
  • 1.  Access Rules IAP 103 - Proper configuration method

    Posted Jan 17, 2018 11:41 AM

    I have an IAP 103 that is setup for Guest. The IAP is connected to a network that is routable to other networks within the office. How can I configure the access rules to deny Guests from accessing internal office networks (192.168.1.1/24, 192.168.2.0/24 and 192.168.3.0/24) but still allow HTTP, HTTPS, and DNS resolution from/to Internet? Typically you configure the access rule to allow first and deny all last but in this case if I followed that method Guest would be able to get to all those networks.

     

    Also, what is the "to master IP" access rule option? Would that allow me to deny anyone on the Guest network from being able to access the IAP?

     

    Thanks

    GM



  • 2.  RE: Access Rules IAP 103 - Proper configuration method

    Posted Jan 17, 2018 04:40 PM
    Assign the following guest final role ACLs should look like this based on your requirements :
    allow dns
    allow dhcp
    Deny internal
    allow http/https

    Please take a look at the free instant training :
    http://www.arubanetworks.com/products/networking/aruba-instant/instant-training/

    Get Outlook for iOS


  • 3.  RE: Access Rules IAP 103 - Proper configuration method

    Posted Jan 17, 2018 05:10 PM
    I see the following deny options: - to all destinations - to a particular server - except to a particular server - to a network - except to a network - to domain name - to master IP - to AP network - to AP IP There is no deny Internal Thanks GM


  • 4.  RE: Access Rules IAP 103 - Proper configuration method

    Posted Jan 17, 2018 05:13 PM
    You will need to add / define the internal network under (to a network)
    If it is more than one subnet if you cant summarize it , you will need to add another deny rule for that other one


  • 5.  RE: Access Rules IAP 103 - Proper configuration method

    Posted Jan 17, 2018 05:17 PM

    ahh.. Sorry. My mind was stuck on the work internal

     

    Thanks

     

    I will try and let ya know.

     

    GM