Aruba Wireless Controller ArubaOS 8

Summary

This document provides scripts to complete the integration of MetaAccess NAC with one more ArubaOS8 Mobility Controllers for Radius Based Enforcement.

Note – A PEF (Policy Enforcement Firewall) license is required on each controller for this integration.

Note – Even when using a Mobility Master node to manage Mobility Controllers at many locations, the tunnel configuration must be applied directly on any Mobility Controller which you wish to integrate with the NAC (i.e. at the /mm/mynode level). The rest of the configuration can be applied at either the Mobility Controller level or the Mobility Master level. You can use show configuration node-heirarchy to see the configuration on the Mobility Master.

Bash
Copy

MetaAccess NAC ArubaOS 8 Integration Script – Mobility Controller

Bash
Copy

Note - Do not apply tunnel keep-alives as they are not compatible with third party vendors such as MetaAccess NAC.

Note - After completing the configuration above, please email a sanitized show run and show switches to your OPSWAT Network Specialist so they can complete the tunnel configuration on the NAC side.

MetaAccess NAC ArubaOS 8 Integration Script – Mobility Master or Mobility Controller

Bash
Copy

####

MetaAccess NAC / ArubaOS 8 - Open Wireless Example

Bash
Copy

MetaAccess NAC / ArubaOS 8 - Secure Wireless Example (802.1x)

Bash
Copy

Note - These steps may be needed if iOS users constantly get disconnected from Aruba SSIDs: Adjust the Global User idle timeout from 30 seconds to 300 seconds:

Bash
Copy
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard