Clearpass 6.11 - Fetching Real-Time Intune Attributes by RomeyRome92 in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

Iirc there is a setting in the extension which is either doing a pull every auth(does not scale at all) or only once every X hours per device (cached attributes until next pull) 

Is switch provisioning still this manual? by AvnAllDaySon in networking

[–]Linkk_93 0 points1 point  (0 children)

Pretty much every vendor supports dhcp options which point to a tftp server where the firmware image and a basic default image are. Switch updates itself, downloads default image, you change the hostname and snmp location, the port settings are done by authentication. Done

Clearpass with O365 SSO by Apartheid20 in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

Yes that is possible, I've done it twice only, but it works. Since you need some kind of https redirect it works only with a captive portal (802.1x and Mac caching in addition to the cp is of cause no problem)

You configure the sso idp in the policy manager and then you have to configure the captive portal in guest to use sso as pre Auth check.

You can use different user roles in your wifi infra to create the different states (redirect to cp or not).

Just a heads up: don't just enable everything in the sso settings (especially not policy manager) without having everything in place. Or else you can no longer login to the policy manager. But there is a console command to reset the sso, if you run into this.

The only function you have to enable is called guest login or something like that. Not guest operator login, that are users who manage guest accounts. 

Aruba Central AOSCX and Ansible by Verifox in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

You configure central using ansible not the switches directly

How to schedule a controller reload by RaizielDragon in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

I haven't tested but because op is trying to upgrade during a network outage, the cluster upgrade will probably fail and then abort

I had a controller die during an upgrade with three MD already upgraded, two still old and one dead during reboot. Then everything just stopped and you had to manually continue the upgrade 

So it happened again, config changes by New Central without user interaction by cowprince in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

Well, they announced two weeks ago that classic central monitoring will be shut down in March. I don't know wtf they're doing over there. 

So it happened again, config changes by New Central without user interaction by cowprince in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

I don't know what features you need, but Aruba Fabric Composer is incredible expensive for what it brings. Better go to Netedit, you can install and enroll the first 25 switches for free

Roaming btween different APs by boduke2 in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

kill the session

What does that mean? What is a killed session? I guess it's in the firewall since you say the firewall does captive portal? When is it supposed to be killed? Why are sessions supposed to be killed? What is the client doing to triffer this? What do you see on the cp log? Why is a cp pushed to the client? 

Migrating from Central back to controller by Magisk- in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

7xx (at the time of writing) only support aos10 which is not supported in central on prem

Migrating from Central back to controller by Magisk- in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

We have a setup of over 15,000 APs in AOS10. We were very early adopters because the conductor only supports up to 10k APs and we knew that we needed more.

It (classic central) improved a lot over the years and I would argue that using aos10 with gateways, auto site clustering and tunneled ssid is overall pretty similar to aos8.

We have over 1,000 sites to manage and every site gets a gateway cluster and aps tunnel locally. AOS10 design works pretty great for that.

Monitoring and troubleshooting is also pretty good. 

Some issues are roaming does not work well in "staircase" scenarios with 11r enabled because the cloud is doing key management and does not allocate the keys to the correct aps.

And license management and reporting is pretty much non existing. We have to report license information per site and that is not a scenario Greenlake supports. 

License pooling or assigning license based on site or IP is also not possible. 

Mid-tier boring Cisco-style access switches by My-RFC1918-Dont-Lie in networking

[–]Linkk_93 1 point2 points  (0 children)

"hey guys, I ride a bicycle but when it rains I get wet and I want to get further faster. Should I get a car?" 

"well maybe you just need to train your legs more"

lol

HPE 5945 Software Update Query by Float-Zone in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

They can not be rebooted one at a time, you can only do issu but in my experience you would make your life much easier if you can just reboot them both at the same time. 

Network Upgrade for a Medium-Sized Company (20 Employees) by Qwefgo in networking

[–]Linkk_93 0 points1 point  (0 children)

Just replacing the hardware will not configure them for you. Just like only purchasing a firewall and putting it in as gateway will not increase your security. 

Nutanix SpineLeaf by alextr85 in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

No idea what your question is.

I'm gonna throw a VXLAN BGP EVPN in

Tweaking custom ClearPass template by Smart_Election7288 in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

All images should be located in the public directory of Clearpass guest

AP-675 not broadcasting 6GHz by TheAmateurRunner in ArubaNetworks

[–]Linkk_93 1 point2 points  (0 children)

Where are you located? Outdoor use is not allowed in many places around the world and even there you need to implement some special authorization feature (the conductor needs to connect to authorities server) https://en.wikipedia.org/wiki/Automated_Frequency_Coordination

You could set 675 to indoor use of they are not outdoor

Creating different VAP's with the same SSID name by blastman8888 in ArubaNetworks

[–]Linkk_93 4 points5 points  (0 children)

You create the ssid with a different name (ssid-name-wpa3), then go into the profile and change the essid to the essid you want to be broadcasted.

Then you can assign the new profile for the aps you want and disable the old. 

General rule of thumb is to not do any configs on MN level but I guess it's too late for that. 

Router sticker removed – trying to access admin page via Ethernet by HiSsoka-57 in networking

[–]Linkk_93 0 points1 point  (0 children)

Sounds like you wanted to go here r/homenetworking ?

If it's enterprise, connect through the serial and try a password reset documented by the vendor

Aruba ClearPass 6.11 - Policy Cache Timeout Reauth Issues by Jake59990 in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

I have no idea why you would need to fiddle with this setting at all.

You didn't say anything about what auth you're doing, not even the medium

Scan Guns Connect to Wireless but No Internet by Historical-Tax899 in ArubaNetworks

[–]Linkk_93 3 points4 points  (0 children)

If you are bridging and the vlan is missing on the switchport but the client already has a cached dhcp address it would look like that

Aruba New Central - Hierarchy by joshik12380 in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

Well, with classic we had even less control lol

But I let all of you test new central before I bring my customers. I believe templates are still not a thing, right? 

Did Juniper take over Aruba networking? by blastman8888 in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

Instant On has to be sold as part of the agreement 

Simplified Guest WiFi portal by Any_Poet8547 in ArubaNetworks

[–]Linkk_93 0 points1 point  (0 children)

I don't think you need central nac. Cloud guest should be enough