Wireless Access

last person joined: 17 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

captiveportal via split-tunnel from Enet1 port on RAP

This thread has been viewed 1 times
  • 1.  captiveportal via split-tunnel from Enet1 port on RAP

    Posted Dec 25, 2012 08:14 PM

    Hi, 

     

    Is it possible to configure captive-portal by split-tunnel from Enet1 port on a Remote-AP. 

     

    Regards,

     

    Yoge



  • 2.  RE: captiveportal via split-tunnel from Enet1 port on RAP

    EMPLOYEE
    Posted Dec 25, 2012 09:57 PM

    Yes.

     



  • 3.  RE: captiveportal via split-tunnel from Enet1 port on RAP

    Posted Dec 26, 2012 06:51 PM

    Thank you CJ.

     

    I am trying this to setup refering to the KB article 825 and will be using Enet1 of AP125 or AP93H.

     

    I will be making the Enet1 port as access vlan 21

     

    I have a doubt in it. The vlan21 interface created on the controller. 

    vlan 21      

    interface vlan 21                                 
            ip address 192.168.199.1 255.255.255.0    
       
    what would be the subnet for the user connected in enet1 ? will it be 192.168.199.0/24 ? 
    what should be the gateway for him? 
     

     



  • 4.  RE: captiveportal via split-tunnel from Enet1 port on RAP

    EMPLOYEE
    Posted Dec 26, 2012 06:59 PM

    @yogendrankp wrote:

    Thank you CJ.

     

    I am trying this to setup refering to the KB article 825 and will be using Enet1 of AP125 or AP93H.

     

    I will be making the Enet1 port as access vlan 21

     

    I have a doubt in it. The vlan21 interface created on the controller. 

    vlan 21      

    interface vlan 21                                 
            ip address 192.168.199.1 255.255.255.0    
       
    what would be the subnet for the user connected in enet1 ? will it be 192.168.199.0/24 ? 
    what should be the gateway for him? 
     

     


    Yes, that will be the subnet.  His gateway would be whatever the DHCP server assigns to him.

     

    The subnet a user is assigned is primarily so that it has an ip address where it can reach the controller and bring up the Captive Portal Page.  The firewall policies for the guest role after successful authentication are normally something like "any any any route src-nat" which will source-nat all traffic out of the ip address of the RAP it is connected to.  So in other words, the default gateway does not really matter.

     

     

    The rules for split tunnel captive portal say that certain traffic will be redirected (route src-nat) out the enet port of the RAP and NOT the default gateway.. http://community.arubanetworks.com/aruba/attachments/aruba/108/205/1/split-tunnel-captive-portal-pdf.pdf

     

     

     



  • 5.  RE: captiveportal via split-tunnel from Enet1 port on RAP

    Posted Jan 24, 2013 01:54 AM

    Thank you CJ 

     

    made it to work.