Wireless Access

last person joined: 22 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Turnkey RAP using Dynamic DNS.

This thread has been viewed 1 times
  • 1.  Turnkey RAP using Dynamic DNS.

    Posted Dec 14, 2018 04:33 PM

    I was wondering if anyone else has configured a turnkey RAP that can be assigned to someone that they could take home and setup themselves.

    We currently are testing remote access points here. I can configure the RAP here and send it home with a remote user but the issue that comes up is when the IP address changes at the user's home it will also need to be changed in our firewall to allow traffic from the new IP on UDP 4500.

     

    What I am thinking is to use Dynamic DNS at the users home. I enter that FQDN in the firewall here and when the IP changes at the remote location the DNS will be changed by the DDNS.

     

    I am thinking that I will need to configure a package that the non-technical user can take home. It will include a router, VOIP phone and a AP303H AP. The AP will be configured for wireless traffic and wired traffic. I'm already thinking that if the person already has a router then we've just set up a double NAT which is not a good idea.  Replacing the user's router is an option but it would probably require someone from IT to pay a visit to set it up. It would also be a big inconvenience to the user.

     

    Has anyone else done something similar?

     

    I'm trying to make it so that someone from the IT department doesn't have to visit the user's home and then find that hopefully the router they use will be able to use DDNS. I am looking to setup as close to plug and play setup as I can get.

     

    Thank you!



  • 2.  RE: Turnkey RAP using Dynamic DNS.

    EMPLOYEE
    Posted Dec 14, 2018 04:38 PM

    You should allow UDP 4500 from anywhere.  Having to maintain and update a list of ip addresses would be painful..



  • 3.  RE: Turnkey RAP using Dynamic DNS.

    Posted Dec 14, 2018 04:40 PM
    That has been discussed. The security guys are not happy about leaving that
    port open.


  • 4.  RE: Turnkey RAP using Dynamic DNS.

    EMPLOYEE
    Posted Dec 14, 2018 04:44 PM

    That is perfectly understandable for site to site VPN, but how do you manage client VPN from tens or hundreds of users from dynamic ip addresses?