Wireless Access

last person joined: 19 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Newb questions

This thread has been viewed 0 times
  • 1.  Newb questions

    Posted Jul 23, 2012 08:54 PM

    We just got our new Aruba gear.  The controller is a 6000 with two M3s using VRRP for redundancy.  A couple questions:

     

    1.  We have one SSID that uses the builing captive portal.  Is there a way to pass handheld devices through this portal without having to use the captive portal to login?  Basically the only devices I want logging in are laptops and desktops.  I would like iphones, ipods, PS3s, Wiis, and android devices to connect and not have to authenticate.

     

    2.  I have multiple AP groups (about 25) each with their own VAP profile, but they all have the same two ESSIDs defined.  Is this a problem?  Will it cause any problems when users roam between VAPs even though they use the same SSID.  We have two SSID the one that is web authed and another that is encryped and 802.1x authed.  I couldn't accomplish this through the GUI.  I had to do it via the command line.  That is why it concerns me.  I want to be able to tweek settings per building in the VAP without affecting APs in other buildings.

     

     

    thanks,

    Brian



  • 2.  RE: Newb questions

    Posted Jul 23, 2012 09:00 PM

    #1 - You could easily utilize User Derivation Rules to set roles that 'by pass' the portal if certain Vendors (MAC addresses) or DHCP fingerprints of devices are detected.   

     

    #2 - Do these Virtual AP profiles share the same VLANs or is every VAP a different set of VLANs ?   



  • 3.  RE: Newb questions

    Posted Jul 23, 2012 09:03 PM

    1.  I'll look into these, thanks.

     

    2.  Some have the same VLAN Pool assigned to them, but some don't.  It's half and half.  I tried reusing VLAN pools in other buildings where I felt I had room in the DHCP scopes to do so.



  • 4.  RE: Newb questions

    Posted Jul 23, 2012 11:08 PM

    Ok, roaming with different VLANs is going to be less than 'seamless' right ?   When a client moves from one VAP to another, and thus changes VLANs it's connectivity will be impacted at layer 3.



  • 5.  RE: Newb questions

    Posted Jul 23, 2012 11:10 PM

    Yep I understand this.  I have mobility IP enabled for the web authed SSID and I have preserve client vlan enabled on the 802.1x authed SSID.  Will these mitigate the roaming problems like I think they will?