Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Limiting Guest Access

This thread has been viewed 4 times
  • 1.  Limiting Guest Access

    Posted Jan 02, 2012 04:20 PM

    We have a captive portal setup on our model 3200 controller. What I have been asked to do is limit a guest login to a specific machine so guests cant give out their login to others who should have access. I'm not sure where to start on this to make it happen.


    #3200


  • 2.  RE: Limiting Guest Access

    EMPLOYEE
    Posted Jan 02, 2012 04:25 PM

    Someone correct me if I am wrong, but I believe you want to set the "Max Sessions" attribute under the guest user role to "1".

     

    From the UG:

     

    Max Sessions

    This configures a maximum number of sessions per user in this role. The default is 65535. You can configure any value between 0-65535.



  • 3.  RE: Limiting Guest Access

    Posted Jan 02, 2012 04:34 PM

    I tried it with a 1 and it didnt help.



  • 4.  RE: Limiting Guest Access

    Posted Jan 02, 2012 05:30 PM

    I realized I wasnt hitting the change button. It is now set to 1 user for the guest access network which is great but I'm needing to limit the users that can use a specific login. I want to have 10 logins and allow only 10 devices at a time. I dont want the same login used twice.



  • 5.  RE: Limiting Guest Access

    EMPLOYEE
    Posted Jan 02, 2012 05:47 PM

    @praetorrian wrote:

    I realized I wasnt hitting the change button. It is now set to 1 user for the guest access network which is great but I'm needing to limit the users that can use a specific login. I want to have 10 logins and allow only 10 devices at a time. I dont want the same login used twice.


    This will allow each user that gets the "guest" role to only login on 1 device with his/her guest login account. I do not know if there is a way to limit the system to only 10 guest login account connections at a time. You could limit the DHCP pool to only 10 addresses, assuming you are using a separate DHCP pool for guests.



  • 6.  RE: Limiting Guest Access

    Posted Jan 02, 2012 05:55 PM

    That sounds like what I want but the behavior I'm seeing when I set it to 1 is only a single user can get on the guest network. Once a second person tries they just get a timeout message when they open their browser.



  • 7.  RE: Limiting Guest Access

    EMPLOYEE
    Posted Jan 02, 2012 05:57 PM
    Are they all using the same login?


  • 8.  RE: Limiting Guest Access

    Posted Jan 02, 2012 05:58 PM

    The second user never gets to the captive portal screen. It just times out.



  • 9.  RE: Limiting Guest Access

    EMPLOYEE
    Posted Jan 02, 2012 06:03 PM
    Right! Because guest is the default role prior to login. Ah. You probably just need to create a new guest role. Make that the role that the guest accounts get. Then set that role to 1 max sessions.


  • 10.  RE: Limiting Guest Access

    EMPLOYEE
    Posted Jan 02, 2012 07:14 PM

    Max sessions is the number of firewall sessions in a role, NOT the number of users.  If you set this parameter to one, only a single user can pass any traffic to a single host, locking everyone else out.  This is NOT what you want.  Please change that parameter back to 65536.

     

     In the Captive Portal Authentication profile, you can use the "Allow only one active user session" parameter so that users can only use their login once when logging into the Captive Portal.  Go to Configuration> Security> Authentication> L3 Authentication> Captive Portal Authentication Profile.  Choose the Captive Portal Authentication Profile that applies to your WLAN and enable the "Allow only one active user session" parameter.  This will allow a user to use his login only once.  There is nothing to limit a user to 10 logins.



  • 11.  RE: Limiting Guest Access
    Best Answer

    EMPLOYEE
    Posted Jan 03, 2012 12:47 AM

    yes using internal controller's CP, you ca neither have 1 user user session or many. If you want to restrict the active user sessions to say 10, you need to do this with an external CP like Amigopd.



  • 12.  RE: Limiting Guest Access

    Posted Jan 03, 2012 11:00 AM

    This worked. Thank you very much.

     



  • 13.  RE: Limiting Guest Access

    EMPLOYEE
    Posted Jan 03, 2012 11:18 AM

    Praettorian,

     

    Glad to hear it works.  Please mark the thread "Solved" when you can.



  • 14.  RE: Limiting Guest Access

    EMPLOYEE
    Posted Jan 02, 2012 07:42 PM
    Ah, thanks Colin. Should probably change the wording in the UG and CRG then, making it "firewall sessions"

    User sessions is a bit ambiguous.


  • 15.  RE: Limiting Guest Access

    EMPLOYEE
    Posted Jan 02, 2012 07:46 PM

    It could use some clarification.  We will notify the documentation team.