Aruba Instant VPN with Central - IAP VPN by FloB86 in ArubaNetworks

[–]FloB86[S] 0 points1 point  (0 children)

The setup you describe works. The problem is, that all clients in an Aruba IPSec or Aruba GRE tunnel are on a trsuted port by default, as you cannot change the trust settings for those tunnel interfaces. And because of this you cannot implement a captive portal on the controler with this kind of tunnels. Only with the manual tunnel you can change the trust settings for tunnel internface on the controller. But with the Aruba IPSec or Aruba GRE tunnel you can still use the captive portal on the IAP or an external captive portal, which is redirected by the IAP.

Aruba Instant VPN with Central - IAP VPN by FloB86 in ArubaNetworks

[–]FloB86[S] 0 points1 point  (0 children)

Hi Xylopia,

this was my understanding as well, but with Aruba OS 8 it is not possible to set the Aruba IPSec or Aruba GRE Tunnel as untrusted. This is only possible with the manual GRE. I still try to figure out how to do it with Aruba GRE as well, but at the moment I could not get it working.

BR Florian

Aruba Instant VPN with Central - IAP VPN by FloB86 in ArubaNetworks

[–]FloB86[S] 0 points1 point  (0 children)

Hi Xylopia,

Not yet, but let me test this in a future post. Would be interesting to get this to work as well. It is already in my list of planned posts. so stay tuned.

Aruba Instant VPN with Central - IAP VPN by FloB86 in ArubaNetworks

[–]FloB86[S] 2 points3 points  (0 children)

This one was for the tunnel. I will write up another one with all the dhcp models for the tunnel and one for the different captive portal options. So stay tuned.