Wireless Access

 View Only
  • 1.  Getting wired connections to AP in mesh config to authenticate with CPPM?

    Posted Jan 29, 2024 12:25 PM

    We have a two Aruba 377 AP's in a mesh configuration so that one of our locations at the edge of the property can have wired connections in the building.

    In the profile for these AP's I have enabled Eth Int 0 port for wired connections, and I can get them to work but currently whatever vlan I have assigned in the 'wired ap>Access mode VLAN' is what the PC's connected to it are receiving, so if I set an employee role even non domain joined devices can get authenticated with no issues if they plug into it.

    I'm sure it is something simple I haven't configured properly, but is there a way to get the devices to authenticate with CPPM properly so they can pick up the proper vlan depending on what type of device is connecting?

    In the attachment 172 would be a guest  vlan would ideally a device would recieve unless it authenticates as an employee device. 



  • 2.  RE: Getting wired connections to AP in mesh config to authenticate with CPPM?

    Posted Jan 30, 2024 02:36 AM

    I recently went trough this configuration.

    Do you have a AAA profile configured for the AP wired port profile?

    I'm using MAC Authentication with CPPM, Clearpass returns the VLAN as Radius:IETF:Tunnel-Private-Group-Id.




  • 3.  RE: Getting wired connections to AP in mesh config to authenticate with CPPM?

    Posted Jan 30, 2024 10:55 AM

    AP wired ports behave in a single domain fashion, first device to authenticate on the port will determine the VLAN behavior for all devices.  If you need multiple devices to connect through the AP wired port then connect a switch and authenticate at that level.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------