Guest access for HPE Aruba Networking Central

In this topic, you will learn how to configure access points managed by HPE Aruba Networking Central to work together with the Portnox™ Cloud captive portal for guest user authentication.

Important:
This guide gives general instructions for integrating Portnox Cloud with specific third-party devices. We try to provide useful examples for common models, but settings can differ between manufacturers, models, and environments. Because of this, we cannot guarantee these steps will work in every case. For questions or problems with RADIUS setup – which is an industry standard and not specific to Portnox – or with device-specific settings and troubleshooting, we recommend checking the device manufacturer’s documentation and contacting their support team. Portnox Support can help when possible, but detailed setup of third-party devices is usually best handled by the manufacturer. We also recommend updating your NAS device firmware to the latest version, as old firmware can cause issues.
Important:
All values in this configuration are examples. Make sure to adjust the configuration to your individual profile names, RADIUS server addresses, ports, and keys by replacing the values that are presented as underlined italics.
Note:
This topic describes the new HPE Aruba Networking Central. HPE is phasing out Classic Central. If you still use Classic Central or an Aruba Mobility Controller, see the following section at the end of this topic: Legacy solutions.
Note:
All tasks in this topic create profiles at the site level. You can also create the profiles at another level, for example, for a site collection, a device group, or a single device. The steps are identical. Only the place where you open the profiles differs. We recommend that you create the guest SSID at the same level as your other WLANs (see the following topic: Wi-Fi employee access for HPE Aruba Networking Central).
Note:
This configuration was tested on the new HPE Aruba Networking Central with an AP-505 access point running AOS 10.8.1.1. The capabilities and the user interface on other versions of the platform may differ.

Create RADIUS server profiles

In this section, you will create authentication server profiles for the Portnox™ Cloud RADIUS servers, and add them to an authentication server group. You will use this server group later when you configure your SSIDs.

  1. In HPE Aruba Networking Central, click on the Config tab in the top-right corner.

  2. In the left-hand side menu, click on the Sites option, and then click on the name of your site.

  3. On the Profiles tab, in the Profiles Management pane, click on the Authentication Server entry in the Security card.

  4. Click on the Create Profile button to create a new authentication server profile.

  5. Configure the new authentication server profile:

    1. In the Name field, enter a name for this server.
    2. Leave the Secure RADIUS checkbox cleared, and leave the RADIUS option selected in the Server Type and Auth Server Mode fields.
    3. In the IP Address/FQDN field, enter the Cloud RADIUS IP value from Portnox Cloud.
    4. In the Shared Secret and Retype Shared Secret fields, enter the Shared Secret value from Portnox Cloud.
    5. In the Authentication Port and Accounting Port fields, enter the Authentication port and Accounting port values from Portnox Cloud.
    6. Click on the Create button.
  6. If you use Cloud RADIUS servers in both regions, repeat the above two steps for the second RADIUS server.

    For example, create one profile for the US server and one profile for the EU server. Adjust the names, IP addresses, and port numbers to your tenant configuration.

  7. Click on the Security entry in the breadcrumb.

  8. In the Profiles Management pane, click on the Manage button in the Authentication Server Group card.

  9. Click on the Create Profile button to create a new authentication server group.

  10. Configure the new authentication server group:

    1. In the Name field, enter a name for this server group.
    2. In the Auth Servers field, select the authentication server profiles that you created earlier, starting with the primary server.
    3. Click on the Create button.

Result: You created an authentication server group that contains the Portnox Cloud RADIUS servers.

Create a captive portal authentication profile

In this section, you will create a captive portal authentication profile that redirects guests to the Portnox™ Cloud captive portal. You will use this profile later when you configure your guest SSID.

Before you begin, configure the guest network in Portnox Cloud and note down the value of the Captive Portal URL field.

Note:
HPE Aruba Networking Central does not require you to add the IP (for walled garden) addresses from Portnox Cloud. The access point automatically allows unauthenticated users to reach the URL of the external captive portal (automatic URL allowlisting).
  1. In HPE Aruba Networking Central, click on the Config tab in the top-right corner.

  2. In the left-hand side menu, click on the Sites option, and then click on the name of your site.

  3. On the Profiles tab, in the Profiles Management pane, click on the Captive Portal Authentication entry in the Security card.

  4. Click on the Create Profile button to create a new captive portal authentication profile.

  5. Configure the new captive portal authentication profile:

    1. In the Name field, enter a name for this profile.
    2. In the URL field, paste the value of the Captive Portal URL, including the leading https://.
    3. Leave the Use HTTPS for authentication checkbox selected.
    4. Optional: In the Post Authentication Redirection URL field, enter the address of the page that guests see after they authenticate.
    5. Click on the Create button.

Result: You created a captive portal authentication profile that points to the Portnox Cloud captive portal.

Create an SSID for guest access

In this section, you will create an open WLAN profile that sends guests to the Portnox™ Cloud captive portal and authenticates them using the Portnox Cloud RADIUS servers.

  1. In HPE Aruba Networking Central, click on the Config tab in the top-right corner.

  2. In the left-hand side menu, click on the Sites option, and then click on the name of your site.

  3. On the Profiles tab, in the Profiles Management pane, click on the WLAN entry in the Wireless card.

  4. Click on the Add WLAN button to create a new WLAN profile.

  5. In the General section, in the Name field, enter a display name for this profile, and in the ESSID Name field, enter the network name that devices see when they search for Wi-Fi networks. Then, in the Bands section, deactivate the 6 GHz checkbox and in the Wi-Fi Protocols section, deactivate the Wi-Fi 7 (802.11be) checkbox.

    Note:
    If 6 GHz is selected in the Bands section or if Wi-Fi 7 (802.11be) is selected in the Wi-Fi Protocols section, the Open option is not available in the Key Management field.
  6. In the Security section:

    1. In the Security Level field, select the Open option.
    2. In the Key Management field, select the Open option.
    3. In the Captive Portal section, in the Type field, select the External Captive Portal option.
    4. In the Captive Portal Profile field, select the captive portal authentication profile that you created earlier.
    5. In the Server Group field, select the authentication server group that you created earlier.
    6. In the Accounting field, select the Use Server Group option.
  7. Leave the remaining settings at their default values unless your environment requires otherwise, and click on the Create button.

Result: You created an open guest SSID that redirects guests to the Portnox Cloud captive portal.

Legacy solutions

Classic Central

In this section, you will learn how to configure access points managed using Aruba Central to work together with the Portnox™ Cloud captive portal for guest user authentication.

Note:
This configuration was tested using the Aruba AP-505 Access Point.
  1. In the left-hand side main menu, click on the Devices option and then, in the right-hand side pane, click on the name of the device that you want to configure.

  2. In the left-hand side menu for the selected device, click on the Device option. Then, in the right-hand side pane, make sure that the WLANs tab is active, and under the Wireless SSIDs list, click on the Add SSID button to add a new SSID.

    Note:
    You can also edit an existing SSID by clicking on its name on the Wireless SSIDs list.
  3. In the Create a New Network wizard, fill in the fields as required for your new SSID until you get to the Security step.
  4. In the Security step:

    1. Set the Security Level slider to the Visitors position.
    2. In the Type field, select the External Captive Portal option.
    3. Click on the  +  icon to the right of the Captive Portal Profile label to create a captive portal profile.
  5. In the External Captive Portal – New window:

    1. In the Name field, enter a name for this captive portal configuration.
    2. In the IP or Hostname field, enter guests.portnox.com.
    3. In the URL field, paste the value of the Captive Portal URL without the leading https://guests.portnox.com but with the leading slash.
      Note:
      You saved the value of Captive Portal URL when you configured the Portnox Cloud guest network.

      For example, the URL field could look like: /b2973887-1274-45c4-91d0-53d1a5eacf20-yoursuffix.

    4. You can leave the default values of the remaining fields or configure them as needed. Then, click on the OK button to save your captive portal configuration.
  6. Back in the Create a New Network wizard’s Security step, click on the  +  icon to the right of the Primary Server label to create a RADIUS server configuration.

    Note:
    If you already created a RADIUS server profile, for example, when configuring wireless access for employees, you can use the existing profile instead of creating a new one.
  7. In the New Server window:

    1. In the Server Type field, select the RADIUS option.
    2. In the Name field, enter a name for this RADIUS server configuration.
    3. In the IP Address/FQDN field, enter your Cloud RADIUS IP, which you obtained when you created the Cloud RADIUS server.
    4. In the Shared Key and Retype Key fields, paste your Shared Secret, also obtained when you created the Cloud RADIUS server.
    5. In the Auth Port field, enter your Authentication port number, also obtained when you created the Cloud RADIUS server.
    6. In the Accounting Port field, enter your Accounting port number, also obtained when you created the Cloud RADIUS server.
    7. In the Timeout (in secs) field, enter 30 to avoid timeouts due to any intermittent Internet connection delays.
    8. Click on the OK button to save your configuration.
  8. Optional: Back in the Create a New Network wizard’s Security step, click on the  +  icon to the right of the Secondary Server label to create a second RADIUS server configuration.

    Note:
    Do this only if your Portnox Cloud tenant is configured with two Cloud RADIUS servers or if you’re using a local RADIUS server in addition to the Cloud RADIUS server. If you already created a secondary RADIUS server profile, for example, when configuring wireless access for employees, you can use the existing profile instead of creating a new one.
  9. Proceed to the Access step of the Create a New Network wizard:

    1. Set the Access rules slider to the Role Based position.
    2. Click on the Add Role button below the Role table to create a new role.
  10. In the Add Role window, enter a name for the new role.

    This role controls network access before the user authenticates with the captive portal. Use a name such as Pre_Authentication.

  11. In the Access rules table, in the Role column, click on the newly created role. In the Access Rules For Selected Roles column, click on the Allow any to all destinations entry. Then, click on the  ✎  icon to edit the rule.

  12. In the Access rules window, in the Destination field, select the To a Domain Name option, and in the Domain Name field, enter guests.portnox.com. Then, click on the OK button to save the edited rule.

  13. Scroll all the way to the bottom of the Access rules pane, activate the checkbox next to the Assign Pre-Authentication Role field, and in the selection field, select the name of the pre-authentication role that you just created and configured.

  14. Complete the remaining steps of the Create a New Network wizard.

Aruba Mobility Controller

In this section, you will learn how to configure an Aruba Mobility Controller to work together with the Portnox™ Cloud captive portal for guest user authentication.

Before you begin configuring your access point, you must configure the guest network in Portnox Cloud and note down the values of the fields: IP (for walled garden) and Captive Portal URL.

Warning:
This topic contains documentation prepared by our support agents more than 12 months ago. It may not cover the newest models or the newest interfaces of NAS devices. We’re working on bringing you updated documentation for NAS devices in the near future. However, the methods of setting up third-party devices may still change when the manufacturers update their firmware or release new models.
  1. In the Aruba Mobility Controller web interface, navigate to Configuration > Authentication > Auth Servers, and add a new server. Then, enter the details of the Portnox Cloud RADIUS server that you created earlier: the IP Address, the Auth port, the Acct port, and the Shared key.

  2. Optional: Repeat for the other Portnox Cloud RADIUS server, if needed.
  3. Navigate to Configuration > WLAN and add a new SSID or edit an existing SSID.
    1. In the General tab, in Primary usage, select Guest.

    2. In the Security tab, select ClearPass or other external Captive Portal.
    3. In Auth servers, select the RADIUS server or servers that you configured earlier.
    4. In Host, enter https://guests.portnox.com.
    5. In Page, enter the remaining part of the Captive Portal URL that you obtained when you configured the guest network in Portnox Cloud.

      For example, if Captive Portal URL is https://guests.portnox.com/12345-12345-12345, in Page, enter /12345-12345-12345.