Wireless Access

last person joined: 19 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

After integrating Controller with active Directory can I create roles based on AD group?

This thread has been viewed 4 times
  • 1.  After integrating Controller with active Directory can I create roles based on AD group?

    Posted Jun 14, 2014 11:25 AM

    After integrating controller with active directory can I create roles based on active directory group membership for example

     

    IT group can have full access to everything but  accountatnt have no access at all.



  • 2.  RE: After integrating Controller with active Directory can I create roles based on AD group?

    Posted Jun 14, 2014 11:39 AM
    You can server derivation rules assigning a role based on a matching filter-Id configured in AD


  • 3.  RE: After integrating Controller with active Directory can I create roles based on AD group?

    Posted Jun 22, 2014 08:40 AM

    can you do that with AD integration? i know you can with radius, but is that what the OP is asking?



  • 4.  RE: After integrating Controller with active Directory can I create roles based on AD group?

    MVP
    Posted Jun 22, 2014 08:48 AM

    You can't do that with straight up ldap as far as I know. EDIT: I stand corrected, see below.

    You can however set up a radius server (Clearpass, NPS, .. ) and use that to return roles depending on AD group membership.

     

    With an Aruba controller you can have your radius server return the aruba vsa aruba-user-role (amongs many more) to have this applied to the user. No need to go into server derivation rules and the likes even.

     

     



  • 5.  RE: After integrating Controller with active Directory can I create roles based on AD group?

    EMPLOYEE
    Posted Jun 22, 2014 09:16 AM

    Koenv

     

    You can change a device's role  based on an attribute  in with LDAP:

     

    http://community.arubanetworks.com/t5/ArubaOS-and-Controllers/LDAP-server-Server-Rules/m-p/2235/highlight/true#M461