Wireless Access

last person joined: 12 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Untrusted wireless VLANs

This thread has been viewed 1 times
  • 1.  Untrusted wireless VLANs

    Posted Feb 23, 2017 04:35 AM

    I've been reading through the AOS guide regarding port and VLAN trusts. It only goes into detail regarding the wired traffic - I wondered if this has any any effect on wireless traffic on an open SSID?



  • 2.  RE: Untrusted wireless VLANs

    Posted Feb 23, 2017 05:17 AM
    It does, what are you trying to do ?

    Get Outlook for iOS


  • 3.  RE: Untrusted wireless VLANs

    Posted Feb 23, 2017 05:17 AM
    It does, what are you trying to do ?

    Get Outlook for iOS


  • 4.  RE: Untrusted wireless VLANs

    Posted Feb 23, 2017 05:21 AM

    I am trying to find out whether the trusted/untrusted status of a physical port affects wireless clients traffic.



  • 5.  RE: Untrusted wireless VLANs

    Posted Feb 23, 2017 05:26 AM

    You can classify wired traffic based not only on the incoming physical port but also on the VLAN associated with the port carrying traffic. For eg, say the user is connected on VLAN 10 and needs to pass traffic through wired port 1/0. If VLAN 10 on that wired port is marked as untrusted then any traffic on VLAN 10 through that port is marked as untrusted.
     
    When you define a physical port or a VLAN associated to that port as untrusted, traffic passing through that port needs to go through a predefined access control list policy. You can set a range of VLANs as trusted or untrusted on a trunk port.
     
    Following table lists the various port/VLAN combination to determine if the user traffic is trusted or untrusted:


    PortVLANTraffic Status
    TrustedTrustedTrusted
    UntrustedUntrustedUntrusted
    UntrustedTrustedUntrusted
    TrustedUntrustedUntrusted

    Environment : This article applies to all controller models and OS versions.

     

    read more here:

    http://community.arubanetworks.com/t5/Controller-Based-WLANs/How-to-configure-a-port-or-a-VLAN-to-be-trusted-or-untrusted/ta-p/187924



  • 6.  RE: Untrusted wireless VLANs

    Posted Feb 23, 2017 05:30 AM

    I understand all that however, back to my original question - does this affect "Wireless" traffic?



  • 7.  RE: Untrusted wireless VLANs

    Posted Feb 23, 2017 05:33 AM

    All the traffic of the clients passing via tunnel to the controller,if that controller passing the traffic to to an untrusted VLAN , so all the traffic inside that VLAN will be untrsusted.



  • 8.  RE: Untrusted wireless VLANs

    Posted Feb 23, 2017 05:43 AM

    Lets simplify - rather than talking about trusted and untrusted VLAN interaction, if all VLANs are trusted but the port is untrusted will wireless traffic be affected by the untrusted port status?



  • 9.  RE: Untrusted wireless VLANs
    Best Answer

    Posted Feb 23, 2017 05:45 AM
    Traffic will be untrusted

    Get Outlook for iOS


  • 10.  RE: Untrusted wireless VLANs

    Posted Feb 23, 2017 05:47 AM

    Thanks Victor.



  • 11.  RE: Untrusted wireless VLANs

    Posted Feb 23, 2017 05:45 AM
    Traffic will be untrusted

    Get Outlook for iOS