Wireless Access

 View Only
  • 1.  bridge mode SSID queries

    Posted Sep 04, 2020 07:14 AM

    Hi Team,

     

    Would like to know if we can push roles and VLANs from ISE server to controller for bridge mode ssid?

     

    Bridge mode SSID normally checks ap uplink acl and not user role defined in aaa profile, is that correct?

     

    Thank you!



  • 2.  RE: bridge mode SSID queries

    Posted Sep 04, 2020 08:57 AM

    You can send the role with Aruba-User-Role VSA and the user VLAN with Aruba-User-VLAN VSA.  The AP uplink ACL only refers to traffic that is coming into the AP unsolicited.



  • 3.  RE: bridge mode SSID queries

    Posted Sep 04, 2020 09:13 AM

    Hi Colin,

     

    Thank you for your response. So can we use VSA for bridge mode SSID as well?

    Do we have to map anything in ap uplink acl?

    Will SDR work in bridge mode?



  • 4.  RE: bridge mode SSID queries

    Posted Sep 04, 2020 11:25 AM

    Double checking it, VLAN derivation (through VSAs or SDR) do not work in bridge mode, unfortunately:  https://community.arubanetworks.com/t5/Controller-Based-WLANs/Which-of-the-derived-vlans-take-priority-if-UDR-MAC-auth-and/ta-p/177432

     

    Sorry for misleading you.



  • 5.  RE: bridge mode SSID queries

    Posted Sep 07, 2020 04:14 AM

    Hi Collin,

     

    Thank you so much for the update. I would like to know if role derivation can be done in bridge mode?

     

    Thank you!

     



  • 6.  RE: bridge mode SSID queries

    Posted Sep 07, 2020 04:41 AM

    Role derivation, yes.



  • 7.  RE: bridge mode SSID queries

    Posted Sep 07, 2020 07:37 AM

    Hi Collin,

     

    Thank you for your response. However, from the below link, it is stated VLAN derivation will work from 6.1 but I do not think so. Can you please confirm?

     

     
    Also, Role derivation works in bridge mode which means we can push a role from server to controller and it should be present in controller. But for bridge mode, we check the ap uplink acl present in ap system-profile so will role be pushed from server to a bridge mode client?
     
    Thank you!
     
     


  • 8.  RE: bridge mode SSID queries

    Posted Sep 07, 2020 08:05 AM

    Feel free to open a support case with technical support.  It has been awhile since I have seen that issue.  You could be running into a bug with VLAN derivation on bridge SSIDs or it is not supposed to work;  I don't remember.

     

    Also ask them about the ap-uplink-acl.