CONFIGURACIÓN WLAN INVITADOS EN ARUBA Y EN LOS SWITCH ENTERASYS Guest WLAN configuration 1 Configure guest VLAN 2 Setup guest AAA server 3 Configure guest accounts 4 Configure guest DHCP services 5 Configure guest SSID 6 Determine guest access policies and rights 7 Define security obects 8 Define guest access scope 9 Configure guest access policies 10 Configure guest user roles 11 Configure guest authentication 12 Configure the first guest laptop Backing up te s!ste" 13 !ac"up the controller
Caso práctico: Red 192.168.3.0/24, Gateway 192.168.3.1 Quereos co!"#urar u! $witc% &!terasys '2G124(12) co! u!a *+- para dar sericio a os 3 )s ue ora! parte de u!a +- u!to co! u! co!troador rua. $upo!eos ue cada ) se e!cue!tra e! u!a pa!ta disti!ta, por o ue creareos u!a *+- por cada pa!ta, e! e switc%: 1. Coo e! e! todos os os switc% switc% e5iste e5iste por por deecto deecto a *+- 1 coo coo i!tera i!tera de #esti7!. 2. Coproa Coproaos os a a direcci7! direcci7! ) de de switc% switc% s%ow co!"# ip. ip. 192.168.3.60/24 3. Creaos Creaos u!a u!a !uea !uea *+- por cada cada ) de pa!ta, pa!ta, e! !uest !uestro ro caso as as *+- 10,20 y 30 set set a! create 10,20,30. 10,20,30 . 4. si#!aos si#!aos u! !ore !ore descript descriptio io ;)s ;)s<rua <rua= = set set a! !ae 600 )s<rua. )s<rua . >. !dicaos !dicaos os os puertos puertos ue particip participa! a! de a *+- 600, 600, e! !uestr !uestro o caso usaos os puertos #e.1.1, #e.1.3 y #e.1.> para co!ectar os 3 )s: )s: set port a! #e.1.1 10 odiy(e#ress set port a! #e.1.2 20 odiy(e#ress set port a! #e.1.3 30 odiy(e#ress +as traas pasa! si! etiuetar u!ta##ed. Ojo este comando e!m!na ot"as VLAN #$e e%!stan en esos &$e"tos . &! e co!troador tai?! creaos as *+-: i!terace a! 10 ip address 192.168.10.2>4 2>>.2>>.2>>.0 @ i!terace a! 10 ip !at i!side @ i!terace a! 10 !o ip i#p pro5y @ i!terace a! 10 !o ip i#p s!oopi!# @
i!terace a! 10 !o ip6 d @ i!terace a! 10 !o cc(optiiatio! i!terace a! 20 ip address 192.168.20.2>4 2>>.2>>.2>>.0 @ i!terace a! 20 ip !at i!side @ i!terace a! 20 !o ip i#p pro5y @ i!terace a! 20 !o ip i#p s!oopi!# @ i!terace a! 20 !o ip6 d @ i!terace a! 20 !o cc(optiiatio! i!terace a! 30 ip address 192.168.30.2>4 2>>.2>>.2>>.0 @ i!terace a! 30 ip !at i!side @ i!terace a! 30 !o ip i#p pro5y @ i!terace a! 30 !o ip i#p s!oopi!# @ i!terace a! 30 !o ip6 d @ i!terace a! 30 !o cc(optiiatio!
#onfiguring te Guest $LAN
i!terace a! 900 ip address 192.168.200.20 2>>.2>>.2>>.0 @ i!terace a! 900 ip !at i!side @ i!terace a! 900 !o ip i#p pro5y @ i!terace a! 900 !o ip i#p s!oopi!# @ i!terace a! 900 !o ip6 d @ i!terace a! 900 !o cc(optiiatio! #onfiguring Guest %'
ip d%cp poo A#uest
>.2>>.2>>.0 #onfiguring Guest Autentication #reating a guest account a("inistrator ro)e guest-provisioning Guest accounts Here is the procedure to test AAA communications #ith the internal authentication database$ 1 SSH to the controller and login 2 %nter the follo#ing commands$ (Aruba-master) # show aaa auth-server Auth Server Table Pri Name Type IP addr AuthPort Status Inservice Applied match-essid match-FQN trim-FQN --- ---- ---- ------- -------- ------ --------- ------ ----------- ---------- --------! Internal "ocal !$%$&&$&& n'a nabled es SecureI & *adius! *adius !$%$&&$&+% !,!& nabled es (Aruba-master) # aaa test-server Internal guest100 GoAruba Authentication successul
#eckpoint* &e no# have an operational master Aruba controller that is configured #ith$ ( ')uest VLAN ('&or"ing AAA server guests
#onfiguring te Guest ++,% *samos el #i+ard
Con e comando show vlan o'tenemos esta !n(o"mac!)n* +ans #$e e%!sten , s$s &$e"tos act!+os '2su(s%ow a! '2su(s%ow a! *+-: 1
-D&: D-G&D&-E
*+- Eype: 'eaut ress )orts #e.1.12 Foridde! ress )orts -o!e. !ta##ed ports #e.1.12
*+-: 10
-D&: )+-E<1
*+- Eype: )era!e!t ress )orts #e.1.1, #e.1.12 Foridde! ress )orts -o!e. !ta##ed ports #e.1.1
*+-: 20
-D&: )+-E<2
*+- Eype: )era!e!t ress )orts #e.1.2, #e.1.12 Foridde! ress )orts -o!e. !ta##ed ports #e.1.2
*+-: 30
-D&: )+-E<3
*+- Eype: )era!e!t ress )orts #e.1.3, #e.1.12 Foridde! ress )orts -o!e. !ta##ed ports #e.1.3
*+-: 100
-D&:
*+- Eype: )era!e!t ress )orts #e.1.1(3, #e.1.12 Foridde! ress )orts -o!e. !ta##ed ports -o!e. *+-: 900
-D&:
*+- Eype: )era!e!t ress )orts #e.1.1(3, #e.1.12 Foridde! ress )orts -o!e. !ta##ed ports -o!e. -ota: )uertos actios ress )orts H )uertos !o etiuetados !ta##ed ports I )uertos etiuetados Ea##ed ports.
Con e comando show vlan static o'tenemos esta !n(o"mac!)n
'2su(s%ow a! static *+-: 1
-D&: '&F+E *+-
*+- Eype: 'eaut ress )orts #e.1.4(6, #e.1.8(11, a#.0.1(6 Foridde! ress )orts
-o!e. !ta##ed ports #e.1.4(6, #e.1.8(11, a#.0.1(6
*+-: 600
-D&:
*+- Eype: )era!e!t ress )orts #e.1.1(3, #e.1.>, #e.1.J, #e.1.12 Foridde! ress )orts -o!e. !ta##ed ports #e.1.1(3, #e.1.J, #e.1.12
-ost"a" a VLAN de con./$"ac!)n '2su(s%ow %ost a! Kost a! is 1
-ost"a" os &$e"tos en cada VLAN '2su(s%ow port e#ress
)ort -uer
*a!
ress
Re#istratio!
d
$tatus
$tatus
(((((((((((((((((((((((((((((((((((((((((((((((((((((((((((( #e.1.1
600
u!ta##ed
static
#e.1.2
600
u!ta##ed
static
#e.1.3
600
u!ta##ed
static
#e.1.>
1
#e.1.>
600
u!ta##ed ta##ed
static static
-ost"a" e 0VID de cada &$e"to '2su(s%ow port a! #e.1.1 is set to 600 #e.1.2 is set to 600 #e.1.3 is set to 600 #e.1.4 is set to 1 #e.1.> is set to 1 #e.1.6 is set to 1 #e.1.J is set to 600 #e.1.8 is set to 1 #e.1.9 is set to 1 #e.1.10 is set to 1 #e.1.11 is set to 1 #e.1.12 is set to 600 a#.0.1 is set to 1 a#.0.2 is set to 1 a#.0.3 is set to 1 a#.0.4 is set to 1 a#.0.> is set to 1 a#.0.6 is set to 1
-ost"a" a con./$"ac!)n de os &$e"tos '2su(s%ow co!"# port E%is coa!d s%ows !o!(deaut co!"#uratio!s o!y. se Ls%ow co!"# aL to s%ow ot% deaut a!d !o!(deaut co!"#uratio!s.
e#i! @
MNNNNN -O-('&F+E CO-FGREO- NNNNN @ @ M Firware Reisio!: 06.03.08.0012 @
Mport set port a! #e.1.1 600 set port a! #e.1.2 600 set port a! #e.1.3 600 set port a! #e.1.J 600 set port a! #e.1.12 600 @ e!d
-ost"a" e estado de cada &$e"to '2su(s%ow port status ias )ort
Oper
di! $peed
tru!cated $tatus $tatus ps
'upe5 Eype
((((((((( (((((((((((( ((((((( ((((((( ((((((((( ((((((( (((((((((((( #e.1.1
p
p
100.0D
#e.1.2
p
p
1.0G
#e.1.3
p
p
100.0D
u
#e.1.4
'ow!
-/
-/
#e.1.>
p
#e.1.6
'ow!
p p p
1.0G -/
u u
u -/
PaseE R4>/)o& PaseE R4>/)o& PaseE R4>/)o& PaseE R4>/)o& PaseE R4>/)o& PaseE R4>/)o&
#e.1.J
'ow!
p
-/
-/
PaseE R4>/)o&
#e.1.8
'ow!
p
-/
-/
PaseE R4>/)o&
#e.1.9
'ow!
p
-/
-/
PaseE R4>/)o&
#e.1.10
'ow!
p
-/
-/
PaseE R4>/)o&
#e.1.11
'ow!
p
-/
-/
Coo R4>/$F)/)o&
#e.1.12
'ow!
p
-/
-/
Coo R4>/$F)/)o&
a#.0.1
'ow!
p
a#
a#.0.2
'ow!
p
a#
a#.0.3
'ow!
p
a#
a#.0.4
'ow!
p
a#
a#.0.>
'ow!
p
a#
a#.0.6
'ow!
p
a#
-ost"a" a con./$"ac!)n I0 '2su(s%ow co!"# ip E%is coa!d s%ows !o!(deaut co!"#uratio!s o!y. se Ls%ow co!"# aL to s%ow ot% deaut a!d !o!(deaut co!"#uratio!s.
e#i! @ MNNNNN -O-('&F+E CO-FGREO- NNNNN @ @ M Firware Reisio!: 06.03.08.0012 @
Mip set ip address 192.168.3.60 asB 2>>.2>>.2>>.0 #ateway 192.168.3.1 @ e!d
-ost"a" a con./$"ac!)n VLAN '2su(s%ow co!"# a! E%is coa!d s%ows !o!(deaut co!"#uratio!s o!y. se Ls%ow co!"# aL to s%ow ot% deaut a!d !o!(deaut co!"#uratio!s.
e#i! @ MNNNNN -O-('&F+E CO-FGREO- NNNNN @ @ M Firware Reisio!: 06.03.08.0012 @
Ma! set a! create 600 set a! !ae 1 AD-G&D&-EA set a! !ae 600 AR&'<RPA cear a! e#ress 1 #e.1.1(3#e.1.J#e.1.12 set a! e#ress 600 #e.1.> ta##ed set a! e#ress 600 #e.1.1(3#e.1.J#e.1.12 u!ta##ed @ e!d