Wireless Access

 View Only
last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Instant AP Roles and Networks Access Rules

This thread has been viewed 18 times
  • 1.  Instant AP Roles and Networks Access Rules

    EMPLOYEE
    Posted Mar 12, 2024 11:06 PM
    I am confused about Roles and Networks Access Rules
     
    Let say I had configured  2 roles Employee & Contractor with access rules.
    Employee user client who logon to wireless network get assigned with Employee role and Contractor user client will get assigned with Contractor role.
     
    Therefore the access rule of employee applied to employee user client and contrctor access rules to contractor user client.
     
    Now I navigate to Configuration > Netorks > edit the corporate SSID and go to (4) Access tab.
     
    There is Access Rules configuration , where default Access Rules = Unrestricted.
     
    Does it mean the access rules for Employee and Contrator is not take effect until we change this Access Rules to Role-based ?


  • 2.  RE: Instant AP Roles and Networks Access Rules

    EMPLOYEE
    Posted Mar 13, 2024 12:01 AM

    the access rules in a particular role gets assigned to all the devices in that user-role.

    The default access rules, in your case " unrestricted access"  gets applied to a default user-role for that WLAN which is the name of your WLAN.

    any device that is not assigned a user role will be in your default user role .



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: Instant AP Roles and Networks Access Rules

    EMPLOYEE
    Posted Mar 13, 2024 12:33 AM

    Hi,

    thanks for replied.

    This mean Access in the WLAN setting is for define access rules for default role. The default role name is auto defined by Instant AP follow the WLAN/SSID name.

    If I select Role-based , what is that mean ?

    I tried select Role-based all roles was shown. Then I save it.

    But I check back , the setting reset back to Unrestricted Access.

     I am still  lost anyway.

    Below is  the help description




  • 4.  RE: Instant AP Roles and Networks Access Rules
    Best Answer

    EMPLOYEE
    Posted Mar 13, 2024 10:58 AM

    If you are using RADIUS to assign the user role then you can ignore that drop-down as the RADIUS assignment has priority.

    If the default role, the one automatically created with the same name as the configured WLAN, has only an "allow all" rule then the "Access Rules" will always show unrestricted.

    If you add rules to the default role then the "Access Rules" drop down will change to "Network-based".

    If you add role assignment rules (derivation rules) then the drop down will change to "Role-based".

    Note, this drop down value will change automatically based on the configuration.  Just setting to "Role-based" while configuring the network does not mean that the value of "Role-based" will always be shown in the drop down field.

    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: Instant AP Roles and Networks Access Rules

    EMPLOYEE
    Posted Mar 13, 2024 11:14 PM

    If you add rules to the default role then the "Access Rules" drop down will change to "Network-based". 

    I tested on IAP, I simply add one rule on the default role and "access Rule" drop down changed to Network-based.

    If you add role assignment rules (derivation rules) then the drop down will change to "Role-based".

    This need to change the "Access Rule" to Role-based then can configure the Role assignment Rules

    I felt odd about this Network Access configuration. No wonder Herman video just said leave it default without further explain it :)

    Any way thank you for provide detail answer.