Wi-Fi employee access for HPE Aruba Networking Central
In this topic, you will learn how to configure access points managed by HPE Aruba Networking Central to work together with Portnox™ Cloud for 802.1X, MAC-based, and IPSK authentication of Wi-Fi connections.
Before you begin, make sure that:
-
Your access points are onboarded, assigned to a site, and managed by the new HPE Aruba Networking Central.
-
The site has an address with a country. By default, the AP System profile takes the country code from the site address. Without a country code, the radios of the access point stay disabled. You can also create an AP System profile for the site and select the country in the Country Code field.
-
Access points that were previously managed by Classic Central are in a Classic Central group with the Allow New Central to overwrite all configurations for this group option selected. Otherwise, the access point keeps broadcasting the SSIDs from its Classic Central group. When you move the access point to such a group, it loses all configuration from the Classic Central group.
Create RADIUS server profiles
In this section, you will create authentication server profiles for the Portnox™ Cloud RADIUS servers, and add them to an authentication server group. You will use this server group later when you configure your SSIDs.
Result: You created an authentication server group that contains the Portnox Cloud RADIUS servers.
Optional: Configure RadSec
Create RadSec server profiles
In this section, you will upload the Cloud RADIUS root certificate and create authentication server profiles that connect to Portnox Cloud RADIUS servers using RadSec.
Before you begin, in Portnox Cloud, go to , select the relevant RADIUS instance, and select . Activate the Enable RADIUS over TLS (RadSec) option, disable the Validate NAS Client Certificate (RadSec) option, and click on the Save button.
Then, click on the Download root certificate link to download the Cloud RADIUS root certificate (DigiCert Trusted Root G4).

Result: You created an authentication server group for RadSec. When you configure an SSID, select this group in the Server Group field instead of the non-RadSec group.
Optional: Configure mutual authentication (mTLS)
In this section, you will create a client certificate for the access point and configure Portnox Cloud to verify it during the RadSec connection.
Result: The access point and Portnox Cloud authenticate each other when the access point connects using RadSec. SSIDs that use the RadSec server group need no changes. They start using mutual authentication as soon as you save the Portnox Cloud setting.
Create an SSID for 802.1X authentication
In this section, you will create a WLAN profile and configure it for WPA2 Enterprise authentication, using the authentication server group that you created earlier.
Result: You created an SSID that authenticates employee Wi-Fi devices using 802.1X and the Portnox Cloud RADIUS servers.
Optional: Create an SSID for MAC-based authentication
This is an optional task. Follow this task only if you want to authenticate devices, such as IoT devices, that do not support 802.1X, using their MAC address instead.
Result: You created a separate SSID that authenticates IoT devices by their MAC address using the Portnox Cloud RADIUS servers on the basis of MAC-based accounts.
Optional: Create an SSID for IPSK authentication
This is an optional task. Follow this task only if you want to authenticate devices using RADIUS-based identity pre-shared keys (IPSK). HPE Aruba Networking Central calls this feature MPSK (Multi Pre-Shared Key).
For more information about IPSK in Portnox Cloud, see the following topic: Create a MAC-based account.
Result: You created a separate SSID that authenticates devices using identity pre-shared keys from Portnox Cloud.
Legacy solutions
Classic Central WPA2 Enterprise
In this section, you will learn how to configure access points managed using Aruba Central to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections.
Classic Central Identity PSK (IPSK)
In this section, you will learn how to configure access points managed using Aruba Central to work together with Portnox™ Cloud and RADIUS-based identity pre-shared key (IPSK) authentication for Wi-Fi connections.
For more information about IPSK in Portnox Cloud, see the following topic: Create a MAC-based account.
Aruba 7000 Series
In this section, you will learn how to configure Aruba 7000 series of controllers with the ArubaOS operating system to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections.






































