Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Authentication on DMZ controller for guest users

This thread has been viewed 2 times
  • 1.  Authentication on DMZ controller for guest users

    Posted Dec 28, 2015 11:31 PM

    I have followed this http://community.arubanetworks.com/t5/Controller-Based-WLANs/How-do-I-redirect-guest-access-across-a-GRE-tunnel-to-a-DMZ/ta-p/183468  docs to configure DMZ for guest controller,

    Here we are using master controller as auth server. Is there a way we can use DMZ controller as auth server ?

     



  • 2.  RE: Authentication on DMZ controller for guest users

    EMPLOYEE
    Posted Dec 28, 2015 11:35 PM

    I cannot open that link.  You can make the DMZ controller do the authentication by making that side of the tunnel untrusted.  The benefit of making the controller that the AP terminates on authenticate the user is that the association and authentication table will have to user on the correct AP, authenticated with the correct name.  If you have the DMZ controller authenticate users, you cannot really track what AP that user is on.



  • 3.  RE: Authentication on DMZ controller for guest users

    Posted Dec 28, 2015 11:58 PM
    Ok, is there anything else required, means any policy or something.
    Or I just need to make the tunnel untrusted.

    Sent from Outlook Mail for Windows 10 phone


  • 4.  RE: Authentication on DMZ controller for guest users

    EMPLOYEE
    Posted Dec 29, 2015 12:05 AM

    Any users that pass through the "untrusted" side of the tunnel will end up in the logon role on the DMZ controller.  That means you need to create a captive portal authentication profile and edit the "logon" role to have that captive portal authentication profile on the DMZ controller.

     

    Please see the post here:  http://community.arubanetworks.com/t5/Controller-Based-WLANs/How-do-I-redirect-guest-access-across-a-GRE-tunnel-to-a-DMZ/ta-p/183468

    Start reading "Configure the DMZ Controller".  *The configuration for the DMZ controller has it natting the user traffic, but that is optional*