OBJECTIVE
In this guide we will see how to configure Aruba Central device in order to use each Access Point as Hotspot for IPERA Starling.
Please note that the images contained in this article may contain outdated configuration data. Therefore, please check the data contained in the article "Parameters for the Configuration" at the bottom of the page, as they are certainly up to date.
ARCHITECTURE
PREREQUISITES
This guide applies to the solution for the active environment of Aruba Central for Cloud-managed networking.
To use an Aruba Central device as a Hotspot, the controller and Access Points must be connected to the Internet.
Configure via Aruba Central
Log in to your Aruba Central account.
Go to Devices > Access Points > Config (top right) > WLANs and click on Add SSID at the bottom left
General Settings
Name (SSID): Guest Wi-Fi (or any name)
Click Next
VLAN Settings
Client IP Assignment: External DHCP server assigned
Client VLAN Assignment: Native VLAN
Click Next
Security Settings
Security Level: Visitors
Type: External Captive Portal
Captive Portal Profile: Click on the plus button
Name: STARLING
Authentication Type: RADIUS Authentication
IP or Hostname: engage.iperawifi.com
URL: /onboarding
Port: 443
Use https: Enabled
Captive portal failure: Deny internet
Automatic URL whitelisting: Enabled
Server offload: Disabled
Prevent frame overlay: Disabled
Use VC IP in Redirect URL: Disabled
Redirect URL: https://engage.iperawifi.com/onboarding?res=success
Click OK to save
Primary Server: Click on the plus button
Server Type: RADIUS
Name: IPERA
Radsec: Disabled
IP address: 35.156.39.198
Shared key: Will be shared separately by IPERA
Retype key: As above
Retry Count: 3
Timeout (in secs): 5
Auth Port: 1812
Accounting Port: 1813
Dead Time (in mins): 5
Click OK to save
Secondary Server: Click on the plus button
Server Type: RADIUS
Name: IPERA_2
Radsec: Disabled
IP address: 35.156.23.166
Shared key: Will be shared separately by IPERA
Retype key: As above
Retry Count: 3
Timeout (in secs): 5
Auth Port: 1812
Accounting Port: 1813
Dead Time (in mins): 5
Click OK to save
LOAD BALANCING: Disabled
Encryption: Disabled
Key Management: Enhanced Open
Click Advanced Settings
Reauth Interval: 24 hrs
Then click Accounting
Accounting: Use authentication servers
Accounting Interval: 3 min
Click Next
Access Settings
- Access rules: Role-based
Under Roles, click on the plus button and enter STARLING as the name
Under Access Rules for STARLING, verify any to any rule is created, if it is not created, click on add rule and add it.
- Access rules: Role-based
Under Roles, click on the plus button and enter PreAuth as the name
Under Access Rules for PreAuth, click on Add Rule and add the following rules:
It is mandatory to add the following domains to ACL
- engage.iperawifi.com
- static.iperawifi.com
If you wish to support social network logins, you need to add rules for domains below for each network you plan to support
|
|
login.microsoftonline.com | accounts.google.com | |
| aadcdn.msauth.net | www.google.com | ||
| login.live.com | fonts.gstatic.com | ||
| akamaihd.net | play.google.com | ||
| aadcdn.msftauth.net | ssl.gstatic.com | ||
| www.facebook.com | accounts.youtube.com | ||
| www.facebook.net | accounts.google.com | ||
| static.xx.fbcdn.net | TikTok (**) | *.tiktok.com | |
| api.twitter.com | firebaseinstallations.googleapis.com | ||
| abs-0.twimg.com | storage.googleapis.com | ||
| pbs.twimg.com | *.ibytedtos.com | ||
|
|
www.linkedin.com | *.tiktokv.com | |
| static.licdn.com | open-api.tiktok.com | ||
| media.licdn.com | www.tiktok.com | ||
| ponf.linkedin.com | *.ttwstatic.com | ||
| platform.linkedin.com | *.tiktokcdn.com | ||
| Apple | www.apple.com | ||
| appleid.apple.com | |||
| appleid.cdn-apple.com | |||
| is4-ssl.mzstatic.com | |||
(*) Please refer to the below URL if you wish to use Microsoft login method
https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/review-admin-consent-requests
(**) Google, Facebook, Twitter, and Apple should be also added for TikTok
Check ASSIGN PRE-AUTHENTICATION ROLE and select PreAuth
Click Finish to complete the setup
Disable SSL Warnings
Navigate Devices > Security > Config
Select Captive Portal: aruba_default
Parameters for the Configuration
For AWS
Primary Radius Server
Login page: https://engage.iperawifi.com/onboarding
Welcome page: https://engage.iperawifi.com/onboarding/?res=success
Redirect URL: https://engage.iperawifi.com/onboarding/?res=success
If the controller switch URL is different from default URL which is securelogin.arubanetworks.com then &switch_url=URL need to be added to the Login Page and Redirect URL.
Login Page: https://engage.iperawifi.com/onboarding/?switch_url=iperawifi.com
Redirect URL: https://engage.iperawifi.com/onboarding/?res=success&switch_url=iperawifi.com
For Azure
Primary Radius Server
Login page: https://me.iperawifi.com/onboarding
Welcome page: https://me.iperawifi.com/onboarding/?res=success
Redirect URL: https://me.iperawifi.com/onboarding/?res=success
If the controller switch URL is different from default URL which is securelogin.arubanetworks.com then &switch_url=URL need to be added to the Login Page and Redirect URL.
Login Page: https://me.iperawifi.com/onboarding/?switch_url=iperawifi.com
Redirect URL: https://me.iperawifi.com/onboarding/?res=success&switch_url=iperawifi.com
Any changes on the above parameters and values will be communicated with IPERA customers in advance.
Comments
0 comments
Please sign in to leave a comment.