Configuring Wired Port Profiles on Instant APs
If the wired clients must be supported on the Instant APs, configure wired port profiles and assign these profiles to the ports of an Instant AP.
The wired ports of an Instant AP allow third-party devices such as VoIPVoice over IP. VoIP allows transmission of voice and multimedia content over an IP network. phones or printers (which support only wired port connections) to connect to the wireless network. You can also configure an ACLAccess Control List. ACL is a common way of restricting certain types of traffic on a physical port. for additional security on the EthernetEthernet is a network protocol for data transmission over LAN. downlink.
To configure wired port profiles on Instant AP, complete the following steps:
1. In the app, set the filter to a group that contains at least one AP.
The dashboard context for the group is displayed.
2. Under , click > .
A list of access points is displayed in the
view.3. Click the icon.
The tabs to configure the access points are displayed.
4. Click , and click the tab.
The Interfaces details page is displayed.
5. Click the accordion.
6. To create a new wired port profile, click .
The Create a New Network pane is displayed.
Complete the configuration for each of the tabs in the Create a New Network page as described in the below sections:
Configuring General Network Profile Settings
To configure general network profile settings, complete the following steps in the
tab:1. Under , enter the following information:
a. —Enter a name.
b. —Select port(s) form the drop-down list.
2. Under section, configure the following parameters:
a. —Select the appropriate value from the Speed and Duplex drop-down list. Contact your network administrator if you need to assign speed and duplex parameters.
b. —Turn on the toggle switch to enable port bonding.
c. —Turn on the toggle switch to enable PoEPower over Ethernet. PoE is a technology for wired Ethernet LANs to carry electric power required for the device in the data cables. The IEEE 802.3af PoE standard provides up to 15.4 W of power on each port..
d. —The indicates if the port is up or down.
e. —Turn on the toggle switch to ensure that all DNSDomain Name System. A DNS server functions as a phone book for the intranet and Internet users. It converts human-readable computer host names into IP addresses and IP addresses into host names. It stores several records for a domain name such as an address 'A' record, name server (NS), and mail exchanger (MX) records. The Address 'A' record is the most important record that is stored in a DNS server, because it provides the required IP address for a network peripheral or element. requests to non-corporate domains on this wired port network are sent to OpenDNS.
f. —Turn on the toggle switch to configure uplink on this wired port profile. If the toggle switch is turned on and this network profile is assigned to a specific port, the port is enabled as an uplink port.
g. —Turn on the toggle switch to enable STPSpanning Tree Protocol. STP is a network protocol that builds a logical loop-free topology for Ethernet networks. on the wired port profile. STP ensures that there are no loops in any bridged Ethernet network and operates on all downlink ports, regardless of forwarding mode. STP does not operate on uplink ports and is supported only on Instant APs with three or more ports. By default, STP is disabled on wired port profiles.
h. —Enter the time duration after which an inactive user needs to be disabled from the network. The user must undergo the authentication process to re-join the network.
i. —Turn on the toggle switch to enable, to support 802.3az Energy Efficient Ethernet (EEE) standard on the device. This option allows the device to consume less power during periods of low data activity. This setting can be enabled for provisioned APs or AP groups through the wired port network. If this feature is enabled for an AP group, APs in the group that do not support 802.3.az ignore this setting. This option is available for Instant APs that support a minimum of Aruba Instant 8.4.0.0 firmware version.
j. —Turn on the toggle switch to disable intra VLANVirtual Local Area Network. In computer networking, a single Layer 2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them through one or more routers; such a domain is referred to as a Virtual Local Area Network, Virtual LAN, or VLAN. traffic. It enables the client isolation and disable all peer-to-peer communication. Client isolation disables inter-client communication by allowing only client to gateway traffic from clients to flow in the network. All other traffic from the client that is not destined to the gateway or configured servers will not be forwarded by the Instant AP. This feature enhances the security of the network and protects it from vulnerabilities.
3. Click .
The
details page is displayed.Configuring VLAN Network Profile Settings
To configure VLAN settings, complete the following steps in the
tab:1. —Specify any of the following modes:
Access—Select this mode to allow the port to carry a single VLAN specified as the native VLAN. If the mode is selected, perform one of the following options:
If the
is set to , proceed to step 6.If the
is set to , specify a value for to indicate the VLAN carried by the port in the mode.Trunk—Select this mode to allow the port to carry packets for multiple VLANs specified as allowed VLANs. If the mode is selected:
Specify the
, enter a list of comma separated digits or ranges, for example 1, 2, 5, or 1-4, or all. The Allowed VLAN refers to the VLANs carried by the port in Access mode.If the
is set to , specify a value for . A VLAN that does not have a VLAN ID tag in the frames is referred to as Native VLAN. You can specify a value within the range of 1-4093.2. —specify any of the following values:
—Select this option to allow the virtual controller to assign IP addresses to the wired clients. When the virtual controller assignment is used, the source IP address is translated for all client traffic that goes through this interface. The virtual controller can also assign a guest VLAN to a wired client. In the section, select when the client VLAN must be assigned to the native VLAN on the network. Select to customize the client VLAN assignment to a specific VLAN, or a range of VLANs. Click the section to view all the named VLANs mapped to VLAN ID. Click and enter the VLAN Name and VLAN ID that is required to be mapped. Clicking populates the named VLAN in the VLAN Name to VLAN ID Mapping table.
—Select this option to allow the clients to receive an IP address from the network to which the Virtual Controller is connected. On selecting this option, the button to create a VLAN is displayed. Create a new VLAN if required.
3. Click .
The
details page is displayed.Configuring Security Settings
To configure security-specific settings, complete the following steps in the
tab:1. On the pane, select the following security options as per your requirement:
MACMedia Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. Authentication Fail-Through. Select any of the following options for authentication server:
—Set the toggle button to enable . Configure the basic parameters such as the authentication server, andNew—On selecting this option, an external RADIUSRemote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allows authentication, authorization, and accounting of remote users who want to access network resources. server must be configured to authenticate the users. For information on configuring an external server, see Configuring Authentication and Security Profiles on Instant APs.
Users link to add the users.
—If an internal server is selected, add the clients that are required to authenticate with the internal RADIUS server. Click theDynamic Load Balancing between Authentication Servers.
—Set the toggle button to enable, if you are using two RADIUS authentication servers, so that the load across the two RADIUS servers is balanced. For more information on the dynamic load balancing mechanism, see—To enable MAC authentication, enable the toggle button. The MAC authentication is disabled by default.
captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users. authentication. For more information on configuring security on captive portal, see Splash Page Profiles.
—Set the toggle button to enable—Set the toggle button to enable, to set security for open network.
2. Enable the option to connect uplink and downlink to a trusted port only.
3. In the field, perform one of the following steps:
Configuring Authentication and Security Profiles on Instant APs.
—To use an internal server, select Internal Server and add the clients that are required to authenticate with the internal RADIUS Server. Click to add the users. To add a new server, click . For information on configuring external servers, see—To add another server for authentication, configure another authentication server.
Dynamic Load Balancing between Authentication Servers.
—Set the toggle button to enable, if you are using two RADIUS authentication servers, to balance the load across these servers. For more information on the dynamic load balancing mechanism, see4. —Set the toggle button to enable, to attempt 802.1X802.1X is an IEEE standard for port-based network access control designed to enhance 802.11 WLAN security. 802.1X provides an authentication framework that allows a user to be authenticated by a central authority. authentication is attempted when the MAC authentication fails.
5. Under the section, configure the following options:
—Set the toggle button to enable, to configure client IP address as calling station ID.
—Select one of the following options:
—Uses the VC ID as the called station ID.
Instant AP as the called station ID.
—Uses the host name of the—Uses the VLAN ID of as the called station ID.
Instant AP as the called station ID.
—Uses the IP address of theInstant AP as the called station ID.
—Uses the MAC address of theThe
detail can be configured even if the is set to disabled.Reauth Interval—Specify the interval at which all associated and authenticated clients must be re-authenticated.
The
pane is displayed.Configuring Access Settings
To configure access-specific settings, complete the following steps:
1. In the tab, turn on the toggle switch to allow downloading of pre-existing user roles. or more information, see ClearPass Policy Manager Certificate Validation for Downloadable Role.
The
feature is optional.The Aruba Instant 8.4.0.0 firmware version with a minimum of ClearPassClearPass is an access management system for creating and enforcing policies across a network to all devices and applications. The ClearPass integrated platform includes applications such as Policy Manager, Guest, Onboard, OnGuard, Insight, Profile, QuickConnect, and so on. server version 6.7.8.
feature is available only for networks that include APs that run a minimum ofAt least one radius server must be configured to apply the External RADIUS Server
feature. For more information on configuring radius server, see2. Click the action corresponding to the server.
The
page is displayed.The
page displays the radius server name. The field is non-editable.3. Enter the CPPM username along with the CPPM authentication credentials for the radius server.
4. Click .
5. Under Access Rules, configure the following access rule parameters:
a. Select any of the following types of access control:
—Allows the users to obtain access based on the roles assigned to them.
—Allows the users to obtain unrestricted access on the port.
—Allows the users to be authenticated based on access rules specified for a network.
b. If the access control is selected:
Under
, select an existing role for which you want to apply the access rules, or click and add the required role. To add a new access rule, click under .The default role with the same name as the network is automatically defined for each network. The default roles cannot be modified or deleted.
Configure role assignment rules. To add a new role assignment rule, click
under . Under :a. Select an attribute.
b. Specify an operator condition.
c. Select a role.
d. Click .
6. Click to create the wired port profile successfully.
Configuring Network Port Profile Assignment
To map the wired port profile to ethernet ports, complete the following steps:
1. In the app, set the filter to a group that contains at least one AP.
The dashboard context for the group is displayed.
2. Under , click > .
A list of access points is displayed in the
view.3. Click the icon.
The tabs to configure the access points are displayed.
4. Click , and click the tab.
The Interfaces details page is displayed.
5. Click the accordion.
The
page is displayed.6. In the section, assign wired port profiles to Ethernet ports:
a. Select a profile from the Ethernet 0/0drop down list.
b. Select the profile from the drop down list.
c. If the Instant AP supports Ethernet 2, Ethernet 3 and Ethernet 4 ports, assign profiles to these ports by selecting a profile from the , , and drop-down list respectively.
7. Click .
Viewing Wired Port Profile Summary
In the
tab, the page displays all the settings configured in the , , , and tabs.Click Save Settings to complete the network profile creation and save the settings.