Wireless Access

last person joined: 17 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Airgroup with Clearpass

This thread has been viewed 1 times
  • 1.  Airgroup with Clearpass

    Posted Aug 02, 2014 09:38 AM

    Hi all,

     

    I am planning to install the code 6.3 to enable airgroup.

     

    We have 3 kinds of users in the network. Domain users, Onboarded BYOD's and Guest. I am allowing domain users to pass through core network. I have dedicated one port directly to core network to pass the traffic.

     

    And for Onboarded devices and guest, they are completely isolated from network  and they assigned to one port which directly goes to firewall ( default gateway for BYOD'S and guests) and then internet.

     

    Now if i want domain users, BYOD's and guest to access bonjour devices which i may place in BYOD subnet. Will all three kinds of users can access bonjour devices or else all three vlans should be able to communicate i mean inter vlan routing. Present situation , these three subnets cant reach each other.

     

     

     

    Thanks

    srikanth



  • 2.  RE: Airgroup with Clearpass
    Best Answer

    EMPLOYEE
    Posted Aug 02, 2014 09:41 AM
    All AirGroup does is proxy and re-advertise the requests. The actual media traffic is unicast so if the Android device is in one segment of the network and the chromecast in another, they will need to be able to reach each other.


  • 3.  RE: Airgroup with Clearpass

    Posted Aug 02, 2014 09:51 AM

    So they should be able to reach other.

     

    So in my case, if i do routing between these 3 segments from firewall would be fine ri8.

     

    Does NATing breaks air group requests or will it forward ??

     

    Warm regards

    srikanth



  • 4.  RE: Airgroup with Clearpass

    EMPLOYEE
    Posted Aug 02, 2014 09:53 AM
    AirGroup does not work across NAT boundaries.


  • 5.  RE: Airgroup with Clearpass

    Posted Aug 02, 2014 09:58 AM
    U mean to say I can't route from firewall or I shoudnt do nating.



  • 6.  RE: Airgroup with Clearpass

    EMPLOYEE
    Posted Aug 02, 2014 10:01 AM
    If you're doing NAT on the firewall, you joules be all set. You just can't cross NAT boundaries.


  • 7.  RE: Airgroup with Clearpass

    Posted Aug 23, 2014 10:03 AM

    I understood that airgroup does proxy for user requests and unicast responses.

     

    Airgroup controller will discover all the devcies providing bonjour services.

    If i am trying to find apple tv from ipad where this both in different vlans. So airgroup jus recieves the mdns query (ipad) and ipad will see the devices which are cached in airgroup table or else it will readvertise across all the vlans on the controller as L3 multicast to discover the bonjour devices.

     



  • 8.  RE: Airgroup with Clearpass

    EMPLOYEE
    Posted Aug 23, 2014 10:28 AM
    At a high level, yes that's correct.


  • 9.  RE: Airgroup with Clearpass

    Posted Aug 23, 2014 10:49 AM

    And will it readvertise  from source ip(ipad) to 224.0.0.251 ??

     

     

    So controller re advertises accross the vlans and gets MDNS responses for MDNS queries and converts them to unicast mdns response and directs to User who initiated MDNS query.

     

    So in that case there is no intervlan routing happening. Controller jus recieving MDNS responses/queries and forwarding to user????



  • 10.  RE: Airgroup with Clearpass

    EMPLOYEE
    Posted Aug 23, 2014 10:53 AM
    The controller actively searches for mDNS and SSDP services and/or listens for advertisements. The controller receives the advertisements and then based on rules and roles, the controller will send a new advertisement out the user VLAN.

    The user subnet needs to be routable to the media server as the actual media transmission is unicast.


  • 11.  RE: Airgroup with Clearpass

    Posted Aug 23, 2014 11:06 AM

    @cappalli wrote:
    The controller actively searches for mDNS and SSDP services and/or listens for advertisements. The controller receives the advertisements and then based on rules and roles, the controller will send a new advertisement out the user VLAN.

    The user subnet needs to be routable to the media server as the actual media transmission is unicast.

     

    We are using airgroup for visibility of  MDNS and SSDP devices across all vlans instead of one vlan.

    Once it is visible ..what we stream will be unicast to bonjour devices.

     

    is it required to have route from media server to user subnet??

     



  • 12.  RE: Airgroup with Clearpass

    EMPLOYEE
    Posted Aug 23, 2014 11:10 AM
    Yes, unicast traffic requires a route to the destination.