Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

RAP 303H: User Ethernet Ports with same VLAN and Authentication as SSID

This thread has been viewed 1 times
  • 1.  RAP 303H: User Ethernet Ports with same VLAN and Authentication as SSID

    Posted Feb 23, 2019 02:01 PM

    Hello,

     

    I have a setup with a 303H and a AOS 8.4 Controller:

     

    -- WLAN SSID with RADIUS Mashine Authentication

    -- VLAN 14

     

    Now i want to use the additional 3 ethernet ports in the same VLAN and also with the RADIUS authentication.

     

    I know about the AP Profiles, but I am not sure.

     

    -- Should I use the same AAA Profile as for the SSID ?

    -- Do I have to configure something in the "AP Wired" Section ?

     

    Thak you and regards



  • 2.  RE: RAP 303H: User Ethernet Ports with same VLAN and Authentication as SSID

    Posted Feb 23, 2019 02:52 PM
    Are you returning the role from the RADIUS server ? Or is it assigned via the AAA profile?



    Thank you

    Victor Fabian

    Pardon typos sent from Mobile


  • 3.  RE: RAP 303H: User Ethernet Ports with same VLAN and Authentication as SSID

    Posted Feb 24, 2019 03:21 AM

    It is assigned via AAA.

     

    The RADIUS just accepts/denies the auth request via group memberships.

     

    Regards



  • 4.  RE: RAP 303H: User Ethernet Ports with same VLAN and Authentication as SSID
    Best Answer

    Posted Feb 24, 2019 02:54 PM
    In that case you can use the same AAA profile you are using for wireless

    You need to configure the wire ap to be set either as an access or trunk if you are planning to have a VoIP phone with laptop/desktop plugged into it (you may need to create different wire ap profiles depending on the use case Mac auth only vs 802.1X and assign the correct profile).

    You can also use both Mac/802.1X on the same port just need to enable L2 failthru if you want to have both authentications in place but that would requiere a different AAA profile to support both L2 auth profiles

    It also needs to be set as untrusted so that the devices are only provided access if those pass authentication

    Thank you

    Victor Fabian

    Pardon typos sent from Mobile


  • 5.  RE: RAP 303H: User Ethernet Ports with same VLAN and Authentication as SSID

    Posted Feb 25, 2019 02:08 AM

    Hi Victor,

     

    I think thats it.

     

    Thank you very much !