07-20-2018 12:06 PM
a bit of an interesting request. We have a controller at one of our local sites(ties back to the master at our main office) which supports about 50 AP's, uses local vlans/subnets and calls in to Clearpass for Radius,OnGuard.. typical communication for our SSID's. One of our local groups at that site(different networking group with another network) wants to use our Aruba solution(call it the business infrastructure) for wireless(so AP and Controller), but have their communication(Radius auth) tie back in to ISE, as it is the solution they are using, when connecting to a different SSID,
I am unsure if I am making any sense, but they basically are asking if a single aruba controller can support both Clearpass and ISE simultaneously depending on which SSID they connect to. If they connect to our "Business" SSID, they get connected through Clearpass and expected behavior is followed. If they decide to connect to "Not Business", ISE is the one answering the Radius request and handles authentication. Considering this is a local controller, I don't see this being possible.
Any thoughts on this potential scenario?
Solved! Go to Solution.
07-20-2018 12:22 PM
It is possible. This is how a "SSID" is constructed:
In your scenario you would just have a different Virtual AP Different SSID profile, different AAA profile and a different server group.
*Answers and views expressed by me on this forum are my own and not necessarily the position of Aruba Networks or Hewlett Packard Enterprise.*
ArubaOS 8.3 User Guide
InstantOS 8.3 User Guide
Airheads Learning Videos