SlideShare une entreprise Scribd logo
1  sur  14
Télécharger pour lire hors ligne
Aruba Instant IAP Setup Notes
June 2012 – Version 3
Aruba Instant (or IAP) is a simple to deploy turn-key WLAN solution consisting of one or more access points. As long as
you have an Ethernet port with connectivity to the Internet you can have the system up and running in less than 10
minutes. Although Aruba Instant is easy to deploy it contains many of the high-end RF and network management
features of an enterprise WLAN solution. Aruba Instant is designed specifically for ease of deployment and proactive
management for small customers or remote locations that don’t have on-site engineers (network or RF) or immediate
access to help desk personnel.
Aruba Instant consists of at least one IAP access point as a virtual controller (VC). The virtual controller resides within
one (any) of the access points. The Access Point (AP) housing the virtual controller functions like any other AP with full
RF scalability. The beauty of Aruba Instant is you don’t know or specify which AP is running the virtual controller. This is
done automatically and provides redundancy should the assigned Master VC have issues, another IAP in the cluster will
automatically become the new Master VC.
You need to configure the first AP during the Aruba Instant deployment. After the initial AP is deployed all subsequent
APs inherit all necessary information from the virtual controller. Aruba Instant continually monitors the network to
determine which AP should function as the virtual controller. When necessary the virtual controller will move from AP to
AP without any impact to the network.
Contents
Easy Setup 1 (DHCP Server) ....................................................................................................................................................2
Easy Setup 2 (no DHCP Server) ...............................................................................................................................................2
Connect to the instant SSID - Login.........................................................................................................................................2
Creating a Basic User / Employee SSID ...................................................................................................................................4
Step 1 – Basic Info...............................................................................................................................................................4
Step 2 – Client IP and VLAN assignment.............................................................................................................................5
Step 3 – Security .................................................................................................................................................................6
Step 4 - Access.....................................................................................................................................................................7
Changing the Setup.............................................................................................................................................................9
Changing the AP Name .......................................................................................................................................................9
Other Settings and Control .....................................................................................................................................................9
Creating a Guest Network SSID.............................................................................................................................................10
Guest Step 1 – Basic Info...................................................................................................................................................10
Guest Step 2 - VLAN section..............................................................................................................................................10
Guest Step 3 - Security......................................................................................................................................................11
Guest Step 4 - Access........................................................................................................................................................12
Setup with DHCP Server
Ensure a DHCP Server is available on the subnet you are connecting the IAP to
Connect to the IAP Console port and start a Terminal emulator
Connect the IAP into a PoE port
Determine the DHCP IP address assigned
After determining the IAP IP Address, use a browser to connect to the IP address and login (default admin/admin)
Setup with no DHCP Server
Connect to the IAP Console port and start a Terminal emulator
Connect the IAP into a PoE port
Watch the Console, “Hit <Enter> to stop autoboot”
Set the following IP settings in the IAP (examples)
apboot> setenv ipaddr 192.168.4.201
apboot> setenv netmask 255.255.255.0
apboot> setenv gatewayip 192.168.4.1
apboot> save (save the entries)
Saving Environment to Flash...
Un-Protected 1 sectors
.done
Erased 1 sectors
Writing
apboot> reset (reset the IAP)
Connect to the instant SSID - Login
Connect the IAP to a network switch and power up the unit. After a short period (booting) the IAP will begin
broadcasting the default SSID. Connect to the “instant” wifi SSID
Then using a web browser
Navigate to the URL “http://instant.arubanetworks.com/” (default admin/admin)
OR
Navigate to the URL “http://{IP Address}/” (default admin/admin)
To get to the login screen
After a successful login you should be presented with the Main dashboard management screen
Note there is only the default “instant” SSID (you connected to)
There are no other IAP’s in the network (this will be configured as the Master VC)
Your PC has been given an IP address from the IAP Virtual Controller
Creating a Basic User / Employee SSID
Easy steps using the GUI
In the upper left corner of the menu select “New”
Step 1 – Basic Info
A new pop-up is displayed, presenting you with a simple 4 step process. Fill in and complete the following on the screen:
Enter a Name (SSID)
Select a Primary usage
Select the Client IP assignment, VLAN or IP address assignment from the IAP
Click on the “Show advanced options” to see additional settings and options – recommend leaving the default settings
as seen here.
It is recommended not changing the advanced options on this page until reading the manual and becoming familiar with
the functions and effects on clients and traffic.
When complete select “Next”
Step 2 – Client IP and VLAN assignment
The IAP allows you to control and select the method of IP address assignment and VLAN of the client. Below is the
default page and settings:
If you have a DHCP server on the network default the Client IP assignment to “Network assigned”
Note the additional settings available in this configuration page:
Statically assign the Client VLAN
Dynamically assign based on Server Derivation rules from the Authentication Server
Step 3 – Security
By default the Security setting presented is WPA2-Persona (Pre-Shared Key). Using the slide bar and pull down menu’s
on the left you can change the level of Authentication and Security as required.
Other Options are Available (next page)
WPA- Enterprise via Internal Database or NEW external Radius Server (via pull down)
Open or MAC address Authentication
(MAC Address via internal database or NEW External Server via pull down)
When complete select “Next”
Step 4 - Access
The default is ‘Unrestricted” access allowing any and all protocols and destinations.
Additional Access settings are available
Network Rules
Using the “New” button you can add Firewall rules as necessary
Role Based - Rules allowing client role setting based on authentication Server Derivation rules (using an external Radius
Server for authentication). Again select New to create the Server Derivation rule / role assignment.
When complete select “Finish”
The new MyTest SSID / network setup is complete
Now disconnect from the default “instant” SSID and reconnect to the new “MyTest” SSID
(Once you create a new SSID the default “instant” SSID will be removed)
Note that new client connections are now provided an IP address from the network DHCP server
Changing the Setup
Anytime you wish to change or adjust these settings click on the SSID name (myemployee) and select “Edit” to modify.
Select “X” to delete
Changing the AP Name
Anytime you wish you can change the AP name (easier to identify by location, room name, etc.) click on the AP name
(the AP MAC address by default) under the Access Point menu and then “Edit”
New Name
Other Settings and Control
The user has control over other a variety of settings within the Instant network accessible from the menu selection
available in the upper right corner of the Main page screen
Creating a Guest Network SSID
With the creation of the internal network SSID (MyTest) use the same basic steps to create a Guest Network SSID.
Click on “New”
Guest Step 1 – Basic Info
Continue with the basic setup steps followed earlier
Enter a Name (SSID)
Select a Primary usage (Guest)
When completed select “Next”
Guest Step 2 - VLAN section
By default this is set to use the Instant VC as the DHCP server providing IP address to clients connecting to the Guest
network.
Guest Step 3 - Security
There are several methods available to authenticate clients on the guest network.
The default screen is presented using the internal database of the Instant VC to authenticate clients. If this method is
selected it is required to enter User names and passwords into the internal database.
Note the “Internal server” shows no users (none have been added yet), to add users click on the “Users” link.
Note the default Guest Splash Screen (use “Preview” to view) presented – requiring a Username and Password.
Add a User
Username
Password
User added to the internal database
Using the pull down (Splash page type) changes the authentication method, (similar to the Aruba controller - username
and password or email address).
This allows clients on to the guest network entering an email address. You can preview the Guest splash page using the
“Preview” link.
After selecting either of these two methods for Guest authentication click “Next”
Guest Step 4 - Access
Default Access - The Access selection screen is displayed. By default Guests are allowed unrestricted access. This can be
changed to suit your security requirements.
Network Based –access rule
In this example Guests are allowed http to a particular server (10.10.10.1)
In this example 10.10.10.1 is the internal IP address of the internet firewall / content filter.
Role Based - Rules allowing client role setting based on authentication Server Derivation rules (using an external Radius
Server for authentication)
Again select New to create the Server Derivation rule / role assignment.
Testing the Guest Network
Connect to the Guest SSID created.
Open a web browser and select an internet site to connect to.
The Guest should be presented with the web access page selected
Enter the Username and Password (previously entered into the internal database).
Ensure you check “I Agree” to the terms.
Click “Login”
You should now be connected to the Guest network.
Viewing the Instant dashboard will show:
Clients connected to the guest network (1)
The Name (Username) the guest entered to log into the network
The IP address assigned by the Instant VC DHCP

Contenu connexe

Tendances

Tendances (20)

6 understanding aruba rf issues
6 understanding aruba rf issues6 understanding aruba rf issues
6 understanding aruba rf issues
 
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
 
Guest Access with ArubaOS
Guest Access with ArubaOSGuest Access with ArubaOS
Guest Access with ArubaOS
 
EMEA Airheads How licensing works in Aruba OS 8.x
EMEA Airheads  How licensing works in Aruba OS 8.xEMEA Airheads  How licensing works in Aruba OS 8.x
EMEA Airheads How licensing works in Aruba OS 8.x
 
Useful cli commands v1
Useful cli commands v1Useful cli commands v1
Useful cli commands v1
 
Managing and Optimizing RF Spectrum for Aruba WLANs
Managing and Optimizing RF Spectrum for Aruba WLANsManaging and Optimizing RF Spectrum for Aruba WLANs
Managing and Optimizing RF Spectrum for Aruba WLANs
 
EMEA Airheads- Instant AP- Instant AP Best Practice Configuration
EMEA Airheads- Instant AP- Instant AP Best Practice ConfigurationEMEA Airheads- Instant AP- Instant AP Best Practice Configuration
EMEA Airheads- Instant AP- Instant AP Best Practice Configuration
 
EMEA Airheads- Aruba Instant AP- VPN Troubleshooting
EMEA Airheads- Aruba Instant AP-  VPN TroubleshootingEMEA Airheads- Aruba Instant AP-  VPN Troubleshooting
EMEA Airheads- Aruba Instant AP- VPN Troubleshooting
 
Outdoor Point-to-Point Deployments
Outdoor Point-to-Point DeploymentsOutdoor Point-to-Point Deployments
Outdoor Point-to-Point Deployments
 
EMEA Airheads- Aruba 8.x Architecture overview & UI Navigation
EMEA Airheads- Aruba 8.x Architecture overview & UI NavigationEMEA Airheads- Aruba 8.x Architecture overview & UI Navigation
EMEA Airheads- Aruba 8.x Architecture overview & UI Navigation
 
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.xEMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
 
EMEA Airheads- ArubaOS - Rogue AP troubleshooting
EMEA Airheads- ArubaOS - Rogue AP troubleshootingEMEA Airheads- ArubaOS - Rogue AP troubleshooting
EMEA Airheads- ArubaOS - Rogue AP troubleshooting
 
Aruba 802.11n Networks Validated Reference Design
Aruba 802.11n Networks Validated Reference DesignAruba 802.11n Networks Validated Reference Design
Aruba 802.11n Networks Validated Reference Design
 
Campus Network Design version 8
Campus Network Design version 8Campus Network Design version 8
Campus Network Design version 8
 
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
EMEA Airheads - Aruba Remote Access Point (RAP) TroubleshootingEMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
 
Aruba instant 6.4.0.2 4.1 user guide
Aruba instant 6.4.0.2 4.1 user guideAruba instant 6.4.0.2 4.1 user guide
Aruba instant 6.4.0.2 4.1 user guide
 
EMEA Airheads- ArubaOS - Cluster Manager
EMEA Airheads- ArubaOS - Cluster ManagerEMEA Airheads- ArubaOS - Cluster Manager
EMEA Airheads- ArubaOS - Cluster Manager
 
EMEA Airheads – Aruba controller features used to optimize performance
EMEA Airheads – Aruba controller features used to optimize performanceEMEA Airheads – Aruba controller features used to optimize performance
EMEA Airheads – Aruba controller features used to optimize performance
 
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba CentralAirheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
 
EMEA Airheads- ArubaOS - Understanding Control-Plane-Security
EMEA Airheads-  ArubaOS - Understanding Control-Plane-SecurityEMEA Airheads-  ArubaOS - Understanding Control-Plane-Security
EMEA Airheads- ArubaOS - Understanding Control-Plane-Security
 

En vedette

Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Aruba, a Hewlett Packard Enterprise company
 
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
Aruba, a Hewlett Packard Enterprise company
 

En vedette (20)

Aruba webinar dorm wi fi design v4
Aruba webinar   dorm wi fi design v4Aruba webinar   dorm wi fi design v4
Aruba webinar dorm wi fi design v4
 
Hello instant 0612_1a
Hello instant 0612_1aHello instant 0612_1a
Hello instant 0612_1a
 
Create a spectrum analysis ap group
Create a spectrum analysis ap groupCreate a spectrum analysis ap group
Create a spectrum analysis ap group
 
Aruba wireless and clear pass 6 integration guide v1.3
Aruba wireless and clear pass 6 integration guide v1.3Aruba wireless and clear pass 6 integration guide v1.3
Aruba wireless and clear pass 6 integration guide v1.3
 
Aruba mobility access switch useful commands v2
Aruba mobility access switch useful commands v2Aruba mobility access switch useful commands v2
Aruba mobility access switch useful commands v2
 
Aruba clearpass ebook_chpt1_final
Aruba clearpass ebook_chpt1_finalAruba clearpass ebook_chpt1_final
Aruba clearpass ebook_chpt1_final
 
Air group configuration howto with clearpass 6 v1.2(1)
Air group configuration howto with clearpass 6 v1.2(1)Air group configuration howto with clearpass 6 v1.2(1)
Air group configuration howto with clearpass 6 v1.2(1)
 
Mac authentication amigopod radius
Mac authentication amigopod radiusMac authentication amigopod radius
Mac authentication amigopod radius
 
2012 ah emea advanced mobility design
2012 ah emea   advanced mobility design2012 ah emea   advanced mobility design
2012 ah emea advanced mobility design
 
2012 ah vegas remote networking fundamentals
2012 ah vegas   remote networking fundamentals2012 ah vegas   remote networking fundamentals
2012 ah vegas remote networking fundamentals
 
Creating an 802 1 xv3
Creating an 802 1 xv3Creating an 802 1 xv3
Creating an 802 1 xv3
 
Security intermediate practical cryptography_certs_and 802.1_x_rich langston...
Security intermediate  practical cryptography_certs_and 802.1_x_rich langston...Security intermediate  practical cryptography_certs_and 802.1_x_rich langston...
Security intermediate practical cryptography_certs_and 802.1_x_rich langston...
 
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
 
Aruba instant the easy button for wireless gokul rajagopalan
Aruba instant the easy button for wireless gokul rajagopalanAruba instant the easy button for wireless gokul rajagopalan
Aruba instant the easy button for wireless gokul rajagopalan
 
Aruba networks webinar_wi-fi_without_interruption_sep20_2012
Aruba networks webinar_wi-fi_without_interruption_sep20_2012Aruba networks webinar_wi-fi_without_interruption_sep20_2012
Aruba networks webinar_wi-fi_without_interruption_sep20_2012
 
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
 
Guest wlan via gu iv3
Guest wlan via gu iv3Guest wlan via gu iv3
Guest wlan via gu iv3
 
Do d directives regarding wireless lan
Do d directives regarding wireless lanDo d directives regarding wireless lan
Do d directives regarding wireless lan
 
2012 ah vegas top10 tips from aruba tac
2012 ah vegas   top10 tips from aruba tac2012 ah vegas   top10 tips from aruba tac
2012 ah vegas top10 tips from aruba tac
 
2012 ah vegas unified access fundamentals
2012 ah vegas   unified access fundamentals2012 ah vegas   unified access fundamentals
2012 ah vegas unified access fundamentals
 

Similaire à Aruba instant iap setup rev3

Ip Phone Apps Training
Ip Phone Apps TrainingIp Phone Apps Training
Ip Phone Apps Training
bhillis1
 

Similaire à Aruba instant iap setup rev3 (20)

Webinar NETGEAR - Nuovi AP Professionali Prosafe WAC720 e WAC730
Webinar NETGEAR - Nuovi AP Professionali Prosafe WAC720 e WAC730Webinar NETGEAR - Nuovi AP Professionali Prosafe WAC720 e WAC730
Webinar NETGEAR - Nuovi AP Professionali Prosafe WAC720 e WAC730
 
Rap split tunnelv2
Rap split tunnelv2Rap split tunnelv2
Rap split tunnelv2
 
Kl 031.30 eng_class_setup_guide_1.2
Kl 031.30 eng_class_setup_guide_1.2Kl 031.30 eng_class_setup_guide_1.2
Kl 031.30 eng_class_setup_guide_1.2
 
Manual repetidor wi fi
Manual repetidor wi fiManual repetidor wi fi
Manual repetidor wi fi
 
ArubaOS 6.3.x Quick Start Guide
ArubaOS 6.3.x Quick Start GuideArubaOS 6.3.x Quick Start Guide
ArubaOS 6.3.x Quick Start Guide
 
Aruba os 6.3.x quick start guide
Aruba os 6.3.x quick start guideAruba os 6.3.x quick start guide
Aruba os 6.3.x quick start guide
 
TLE 10 (ICT): Configuring a Wireless Router
TLE 10 (ICT): Configuring a Wireless RouterTLE 10 (ICT): Configuring a Wireless Router
TLE 10 (ICT): Configuring a Wireless Router
 
Rap installation updated
Rap installation updatedRap installation updated
Rap installation updated
 
Hello instant 0612_1a
Hello instant 0612_1aHello instant 0612_1a
Hello instant 0612_1a
 
Ip Phone Apps Training
Ip Phone Apps TrainingIp Phone Apps Training
Ip Phone Apps Training
 
installation and configuration of informatica server
installation and configuration of informatica serverinstallation and configuration of informatica server
installation and configuration of informatica server
 
Air os qs
Air os qsAir os qs
Air os qs
 
Wi fi ruckus config
Wi fi ruckus configWi fi ruckus config
Wi fi ruckus config
 
Tp link extender setup
Tp link extender setupTp link extender setup
Tp link extender setup
 
How to configure cisco 1242 wireless ap
How to configure cisco 1242 wireless apHow to configure cisco 1242 wireless ap
How to configure cisco 1242 wireless ap
 
Load Balancer Device and Configurations.
Load Balancer Device and Configurations.Load Balancer Device and Configurations.
Load Balancer Device and Configurations.
 
Iuwne10 S02 L02
Iuwne10 S02 L02Iuwne10 S02 L02
Iuwne10 S02 L02
 
Wireless Hotspot Kit
Wireless Hotspot KitWireless Hotspot Kit
Wireless Hotspot Kit
 
Router configuracion acuse 512
Router configuracion acuse 512Router configuracion acuse 512
Router configuracion acuse 512
 
Webinar NETGEAR - La gestione wireless centralizzata con la modalità Ensemble
Webinar NETGEAR - La gestione wireless centralizzata con la modalità EnsembleWebinar NETGEAR - La gestione wireless centralizzata con la modalità Ensemble
Webinar NETGEAR - La gestione wireless centralizzata con la modalità Ensemble
 

Plus de Aruba, a Hewlett Packard Enterprise company

Plus de Aruba, a Hewlett Packard Enterprise company (19)

Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard AgentsAirheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
 
EMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba CentralEMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba Central
 
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS SwitchEMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS Switch
 
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS SwitchEMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
 
Introduction to AirWave 10
Introduction to AirWave 10Introduction to AirWave 10
Introduction to AirWave 10
 
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS SwitchEMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
 
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.xEMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
 
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads-  Getting Started with the ClearPass REST API – CPPMEMEA Airheads-  Getting Started with the ClearPass REST API – CPPM
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
 
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)
 
EMEA Airheads - What does AirMatch do differently?v2
 EMEA Airheads - What does AirMatch do differently?v2 EMEA Airheads - What does AirMatch do differently?v2
EMEA Airheads - What does AirMatch do differently?v2
 
Airheads Meetups: 8400 Presentation
Airheads Meetups: 8400 PresentationAirheads Meetups: 8400 Presentation
Airheads Meetups: 8400 Presentation
 
Airheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau PresentationAirheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau Presentation
 
Airheads Meetups- High density WLAN
Airheads Meetups- High density WLANAirheads Meetups- High density WLAN
Airheads Meetups- High density WLAN
 
Airheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes ArubaAirheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes Aruba
 
EMEA Airheads - Configuring different APIs in Aruba 8.x
EMEA Airheads - Configuring different APIs  in Aruba 8.x EMEA Airheads - Configuring different APIs  in Aruba 8.x
EMEA Airheads - Configuring different APIs in Aruba 8.x
 
EMEA Airheads - Multi zone ap and centralized image upgrade
EMEA Airheads - Multi zone ap and centralized image upgradeEMEA Airheads - Multi zone ap and centralized image upgrade
EMEA Airheads - Multi zone ap and centralized image upgrade
 
Bringing up Aruba Mobility Master, Managed Device & Access Point
Bringing up Aruba Mobility Master, Managed Device & Access PointBringing up Aruba Mobility Master, Managed Device & Access Point
Bringing up Aruba Mobility Master, Managed Device & Access Point
 
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...
 
EMEA Airheads- ClearPass extensions and how they can help
EMEA Airheads-  ClearPass extensions and how they can helpEMEA Airheads-  ClearPass extensions and how they can help
EMEA Airheads- ClearPass extensions and how they can help
 

Dernier

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Dernier (20)

TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 

Aruba instant iap setup rev3

  • 1. Aruba Instant IAP Setup Notes June 2012 – Version 3 Aruba Instant (or IAP) is a simple to deploy turn-key WLAN solution consisting of one or more access points. As long as you have an Ethernet port with connectivity to the Internet you can have the system up and running in less than 10 minutes. Although Aruba Instant is easy to deploy it contains many of the high-end RF and network management features of an enterprise WLAN solution. Aruba Instant is designed specifically for ease of deployment and proactive management for small customers or remote locations that don’t have on-site engineers (network or RF) or immediate access to help desk personnel. Aruba Instant consists of at least one IAP access point as a virtual controller (VC). The virtual controller resides within one (any) of the access points. The Access Point (AP) housing the virtual controller functions like any other AP with full RF scalability. The beauty of Aruba Instant is you don’t know or specify which AP is running the virtual controller. This is done automatically and provides redundancy should the assigned Master VC have issues, another IAP in the cluster will automatically become the new Master VC. You need to configure the first AP during the Aruba Instant deployment. After the initial AP is deployed all subsequent APs inherit all necessary information from the virtual controller. Aruba Instant continually monitors the network to determine which AP should function as the virtual controller. When necessary the virtual controller will move from AP to AP without any impact to the network. Contents Easy Setup 1 (DHCP Server) ....................................................................................................................................................2 Easy Setup 2 (no DHCP Server) ...............................................................................................................................................2 Connect to the instant SSID - Login.........................................................................................................................................2 Creating a Basic User / Employee SSID ...................................................................................................................................4 Step 1 – Basic Info...............................................................................................................................................................4 Step 2 – Client IP and VLAN assignment.............................................................................................................................5 Step 3 – Security .................................................................................................................................................................6 Step 4 - Access.....................................................................................................................................................................7 Changing the Setup.............................................................................................................................................................9 Changing the AP Name .......................................................................................................................................................9 Other Settings and Control .....................................................................................................................................................9 Creating a Guest Network SSID.............................................................................................................................................10 Guest Step 1 – Basic Info...................................................................................................................................................10 Guest Step 2 - VLAN section..............................................................................................................................................10 Guest Step 3 - Security......................................................................................................................................................11 Guest Step 4 - Access........................................................................................................................................................12
  • 2. Setup with DHCP Server Ensure a DHCP Server is available on the subnet you are connecting the IAP to Connect to the IAP Console port and start a Terminal emulator Connect the IAP into a PoE port Determine the DHCP IP address assigned After determining the IAP IP Address, use a browser to connect to the IP address and login (default admin/admin) Setup with no DHCP Server Connect to the IAP Console port and start a Terminal emulator Connect the IAP into a PoE port Watch the Console, “Hit <Enter> to stop autoboot” Set the following IP settings in the IAP (examples) apboot> setenv ipaddr 192.168.4.201 apboot> setenv netmask 255.255.255.0 apboot> setenv gatewayip 192.168.4.1 apboot> save (save the entries) Saving Environment to Flash... Un-Protected 1 sectors .done Erased 1 sectors Writing apboot> reset (reset the IAP) Connect to the instant SSID - Login Connect the IAP to a network switch and power up the unit. After a short period (booting) the IAP will begin broadcasting the default SSID. Connect to the “instant” wifi SSID Then using a web browser Navigate to the URL “http://instant.arubanetworks.com/” (default admin/admin) OR Navigate to the URL “http://{IP Address}/” (default admin/admin)
  • 3. To get to the login screen After a successful login you should be presented with the Main dashboard management screen Note there is only the default “instant” SSID (you connected to) There are no other IAP’s in the network (this will be configured as the Master VC) Your PC has been given an IP address from the IAP Virtual Controller
  • 4. Creating a Basic User / Employee SSID Easy steps using the GUI In the upper left corner of the menu select “New” Step 1 – Basic Info A new pop-up is displayed, presenting you with a simple 4 step process. Fill in and complete the following on the screen: Enter a Name (SSID) Select a Primary usage Select the Client IP assignment, VLAN or IP address assignment from the IAP Click on the “Show advanced options” to see additional settings and options – recommend leaving the default settings as seen here.
  • 5. It is recommended not changing the advanced options on this page until reading the manual and becoming familiar with the functions and effects on clients and traffic. When complete select “Next” Step 2 – Client IP and VLAN assignment The IAP allows you to control and select the method of IP address assignment and VLAN of the client. Below is the default page and settings: If you have a DHCP server on the network default the Client IP assignment to “Network assigned” Note the additional settings available in this configuration page:
  • 6. Statically assign the Client VLAN Dynamically assign based on Server Derivation rules from the Authentication Server Step 3 – Security By default the Security setting presented is WPA2-Persona (Pre-Shared Key). Using the slide bar and pull down menu’s on the left you can change the level of Authentication and Security as required. Other Options are Available (next page) WPA- Enterprise via Internal Database or NEW external Radius Server (via pull down)
  • 7. Open or MAC address Authentication (MAC Address via internal database or NEW External Server via pull down) When complete select “Next” Step 4 - Access The default is ‘Unrestricted” access allowing any and all protocols and destinations. Additional Access settings are available
  • 8. Network Rules Using the “New” button you can add Firewall rules as necessary Role Based - Rules allowing client role setting based on authentication Server Derivation rules (using an external Radius Server for authentication). Again select New to create the Server Derivation rule / role assignment. When complete select “Finish” The new MyTest SSID / network setup is complete Now disconnect from the default “instant” SSID and reconnect to the new “MyTest” SSID (Once you create a new SSID the default “instant” SSID will be removed) Note that new client connections are now provided an IP address from the network DHCP server
  • 9. Changing the Setup Anytime you wish to change or adjust these settings click on the SSID name (myemployee) and select “Edit” to modify. Select “X” to delete Changing the AP Name Anytime you wish you can change the AP name (easier to identify by location, room name, etc.) click on the AP name (the AP MAC address by default) under the Access Point menu and then “Edit” New Name Other Settings and Control The user has control over other a variety of settings within the Instant network accessible from the menu selection available in the upper right corner of the Main page screen
  • 10. Creating a Guest Network SSID With the creation of the internal network SSID (MyTest) use the same basic steps to create a Guest Network SSID. Click on “New” Guest Step 1 – Basic Info Continue with the basic setup steps followed earlier Enter a Name (SSID) Select a Primary usage (Guest) When completed select “Next” Guest Step 2 - VLAN section By default this is set to use the Instant VC as the DHCP server providing IP address to clients connecting to the Guest network.
  • 11. Guest Step 3 - Security There are several methods available to authenticate clients on the guest network. The default screen is presented using the internal database of the Instant VC to authenticate clients. If this method is selected it is required to enter User names and passwords into the internal database. Note the “Internal server” shows no users (none have been added yet), to add users click on the “Users” link. Note the default Guest Splash Screen (use “Preview” to view) presented – requiring a Username and Password. Add a User Username Password User added to the internal database
  • 12. Using the pull down (Splash page type) changes the authentication method, (similar to the Aruba controller - username and password or email address). This allows clients on to the guest network entering an email address. You can preview the Guest splash page using the “Preview” link. After selecting either of these two methods for Guest authentication click “Next” Guest Step 4 - Access Default Access - The Access selection screen is displayed. By default Guests are allowed unrestricted access. This can be changed to suit your security requirements. Network Based –access rule
  • 13. In this example Guests are allowed http to a particular server (10.10.10.1) In this example 10.10.10.1 is the internal IP address of the internet firewall / content filter. Role Based - Rules allowing client role setting based on authentication Server Derivation rules (using an external Radius Server for authentication) Again select New to create the Server Derivation rule / role assignment. Testing the Guest Network Connect to the Guest SSID created. Open a web browser and select an internet site to connect to. The Guest should be presented with the web access page selected Enter the Username and Password (previously entered into the internal database). Ensure you check “I Agree” to the terms. Click “Login” You should now be connected to the Guest network.
  • 14. Viewing the Instant dashboard will show: Clients connected to the guest network (1) The Name (Username) the guest entered to log into the network The IP address assigned by the Instant VC DHCP