Controllerless Networks

 View Only
Expand all | Collapse all

Separate VLAN for each user on Aruba Central

This thread has been viewed 2 times
  • 1.  Separate VLAN for each user on Aruba Central

    Posted Apr 22, 2020 02:47 PM

    I have a Student Residence building that I need to deploy wireless APs in.   I would like to configure that wireless network to allow each student to have their own VLAN in order to emulate a home type environment (personal devices on WLAN can see other personal devices but not devices from other students).

    I have a RADIUS server that will have all the students login information as well as the ability to onboard devices that won't work with WPA2-Enterprise security.

     

    Is this possible to configure with either Aurba Central or Aruba Instant?



  • 2.  RE: Separate VLAN for each user on Aruba Central

    Posted Apr 22, 2020 02:57 PM
    Do you have ClearPass?





    Thank you

    Victor Fabian

    Pardon typos sent from Mobile


  • 3.  RE: Separate VLAN for each user on Aruba Central

    Posted Apr 22, 2020 03:04 PM

    No....but yes

     

    This wireless installation is being treated as a separate network from the main institution's wireless network.  Our institution does have clearpass but I would prefer to do this without using clearpass



  • 4.  RE: Separate VLAN for each user on Aruba Central

    Posted Apr 22, 2020 03:37 PM
    With ClearPass Policy Engine and AirGroup you can accomplish this without having to create separate VLANs per user (I wouldn’t recommend taking that approach)



    Sent from Mail for Windows 10


  • 5.  RE: Separate VLAN for each user on Aruba Central

    Posted Apr 22, 2020 04:05 PM

    Hi, 

     

    Aruba instant can be managed locally through web gui of VC or using Aruba Central or Airwave. Central just provides management of Instant cluster(s). 

     

    Yes you can do it using instant with/without Central using Radius server,



  • 6.  RE: Separate VLAN for each user on Aruba Central

    Posted Apr 23, 2020 09:59 AM

     

    How would you go about setting it up?  My boss is leaning towards paying for cloud (Aruba Central management)



  • 7.  RE: Separate VLAN for each user on Aruba Central

    Posted Apr 23, 2020 02:01 PM
    Hi,

    Assuming you are asking about how to assign students their respective
    Vlans. If thats correct, i have done it using CPPM and TekRadius, you can
    do the same using any 3rd party radius server.

    Please confirm if above is what you are looking for


  • 8.  RE: Separate VLAN for each user on Aruba Central

    Posted Apr 23, 2020 02:04 PM

    sorry I thought you meant you had done it without using clearpass.  So just to confirm....There is no way to do this without leveraging clearpass?



  • 9.  RE: Separate VLAN for each user on Aruba Central

    Posted Apr 23, 2020 02:12 PM
    Hi,

    You can do it without using Clearpass.


  • 10.  RE: Separate VLAN for each user on Aruba Central

    Posted Apr 23, 2020 02:20 PM

    How would you do it without Clearpass?



  • 11.  RE: Separate VLAN for each user on Aruba Central
    Best Answer

    Posted Apr 23, 2020 02:32 PM
    Hi,

    When user authenticates, the radius server will return Aruba-User-Role or
    Aruba-User-Vlan with the value of role/vlan respectively.


  • 12.  RE: Separate VLAN for each user on Aruba Central



  • 13.  RE: Separate VLAN for each user on Aruba Central
    Best Answer

    Posted Apr 23, 2020 02:47 PM
    Hi,

    Yes. You need to configure your Radius server to return aruba-user-role
    attribute if authentication is successful.


  • 14.  RE: Separate VLAN for each user on Aruba Central

    Posted Apr 23, 2020 02:54 PM

    I thought it was possible but my Aruba SE said that I needed to use clearpass. 

    I have a few more questions.

    - Will the user still be able to roam around the building and authenticate to other APs while still maintaining their personal VLAN? 

    - Will I need to assign all the VLANs to the switch ports where the Access Points are plugged in or will the Aruba APs tunnel the appropriate VLANs to the APs?

    Thank you so much!

     



  • 15.  RE: Separate VLAN for each user on Aruba Central

    Posted Apr 23, 2020 03:25 PM
    Hi,

    For your questions

    Will the user still be able to roam around the building and authenticate to
    other APs while still maintaining their personal VLAN?

    Yes, no issues there.

    - Will I need to assign all the VLANs to the switch ports where the Access
    Points are plugged in or will the Aruba APs tunnel the appropriate VLANs to
    the APs?

    There is no tunneling of traffic (management/data) in Aruba Instant like in
    controller appliances. You need to create the required Vlans across your
    switching infrastructure


  • 16.  RE: Separate VLAN for each user on Aruba Central

    Posted Apr 23, 2020 03:27 PM

    Thank you so much for answering all my questions! 



  • 17.  RE: Separate VLAN for each user on Aruba Central

    Posted Apr 23, 2020 03:43 PM
    Hi,

    You are most welcome


  • 18.  RE: Separate VLAN for each user on Aruba Central

    Posted Apr 24, 2020 06:19 AM

    This wireless installation is being treated as a separate network from the main institution's wireless network. Our institution does have clearpass but I would prefer to do this without using clearpass



  • 19.  RE: Separate VLAN for each user on Aruba Central

    Posted Apr 24, 2020 06:28 AM

    Hi, 

     

    You want to do it without clearpass or without any radius server?