Wi-Fi employee access for HPE Aruba Networking Central

In this topic, you will learn how to configure access points managed by HPE Aruba Networking Central to work together with Portnox™ Cloud for 802.1X, MAC-based, and IPSK authentication of Wi-Fi connections.

Before you begin, make sure that:

  • Your access points are onboarded, assigned to a site, and managed by the new HPE Aruba Networking Central.

  • The site has an address with a country. By default, the AP System profile takes the country code from the site address. Without a country code, the radios of the access point stay disabled. You can also create an AP System profile for the site and select the country in the Country Code field.

  • Access points that were previously managed by Classic Central are in a Classic Central group with the Allow New Central to overwrite all configurations for this group option selected. Otherwise, the access point keeps broadcasting the SSIDs from its Classic Central group. When you move the access point to such a group, it loses all configuration from the Classic Central group.

Important:
This guide gives general instructions for integrating Portnox Cloud with specific third-party devices. We try to provide useful examples for common models, but settings can differ between manufacturers, models, and environments. Because of this, we cannot guarantee these steps will work in every case. For questions or problems with RADIUS setup – which is an industry standard and not specific to Portnox – or with device-specific settings and troubleshooting, we recommend checking the device manufacturer’s documentation and contacting their support team. Portnox Support can help when possible, but detailed setup of third-party devices is usually best handled by the manufacturer. We also recommend updating your NAS device firmware to the latest version, as old firmware can cause issues.
Important:
All values in this configuration are examples. Make sure to adjust the configuration to your individual profile names, RADIUS server addresses, ports, and keys by replacing the values that are presented as underlined italics.
Note:
This topic describes the new HPE Aruba Networking Central. HPE is phasing out Classic Central. If you still use Classic Central, see the following section at the end of this topic: Legacy solutions.
Note:
All tasks in this topic create profiles at the site level. You can also create the profiles at another level, for example, for a site collection, a device group, or a single device. The steps are identical. Only the place where you open the profiles differs.
Note:
This configuration was tested on the new HPE Aruba Networking Central with an AP-505 access point running AOS 10.8.1.1. The capabilities and the user interface on other versions of the platform may differ.

Create RADIUS server profiles

In this section, you will create authentication server profiles for the Portnox™ Cloud RADIUS servers, and add them to an authentication server group. You will use this server group later when you configure your SSIDs.

  1. In HPE Aruba Networking Central, click on the Config tab in the top-right corner.

  2. In the left-hand side menu, click on the Sites option, and then click on the name of your site.

  3. On the Profiles tab, in the Profiles Management pane, click on the Authentication Server entry in the Security card.

  4. Click on the Create Profile button to create a new authentication server profile.

  5. Configure the new authentication server profile:

    1. In the Name field, enter a name for this server.
    2. Leave the Secure RADIUS checkbox cleared, and leave the RADIUS option selected in the Server Type and Auth Server Mode fields.
    3. In the IP Address/FQDN field, enter the Cloud RADIUS IP value from Portnox Cloud.
    4. In the Shared Secret and Retype Shared Secret fields, enter the Shared Secret value from Portnox Cloud.
    5. In the Authentication Port and Accounting Port fields, enter the Authentication port and Accounting port values from Portnox Cloud.
    6. Click on the Create button.
  6. If you use Cloud RADIUS servers in both regions, repeat the above two steps for the second RADIUS server.

    For example, create one profile for the US server and one profile for the EU server. Adjust the names, IP addresses, and port numbers to your tenant configuration.

  7. Click on the Security entry in the breadcrumb.

  8. In the Profiles Management pane, click on the Manage button in the Authentication Server Group card.

  9. Click on the Create Profile button to create a new authentication server group.

  10. Configure the new authentication server group:

    1. In the Name field, enter a name for this server group.
    2. In the Auth Servers field, select the authentication server profiles that you created earlier, starting with the primary server.
    3. Click on the Create button.

Result: You created an authentication server group that contains the Portnox Cloud RADIUS servers.

Optional: Configure RadSec

Create RadSec server profiles

In this section, you will upload the Cloud RADIUS root certificate and create authentication server profiles that connect to Portnox Cloud RADIUS servers using RadSec.

Note:
In this section, you create a one-way RadSec connection. The access point verifies Portnox Cloud, but Portnox Cloud does not verify the access point. To enable mutual verification, see the next section.

Before you begin, in Portnox Cloud, go to Settings > Services > CLOUD RADIUS SERVICE > Cloud RADIUS instance, select the relevant RADIUS instance, and select  ⋮  > Edit. Activate the Enable RADIUS over TLS (RadSec) option, disable the Validate NAS Client Certificate (RadSec) option, and click on the Save button.

Then, click on the Download root certificate link to download the Cloud RADIUS root certificate (DigiCert Trusted Root G4).

  1. In HPE Aruba Networking Central, in the left-hand side toolbar, click on the Menu icon.

  2. Click on the Manage button in the Certificate Management card.

  3. Click on the Add button to add a new certificate.

  4. Upload the Cloud RADIUS root certificate:

    1. In the Name field, enter a name for the certificate.
    2. In the Type field, select the CA option.
    3. In the Format field, select the DER option.
    4. In the Upload Certificate field, click on the Select File button, and select the root certificate that you downloaded from Portnox Cloud.
    5. Click on the Add button.
  5. In HPE Aruba Networking Central, in the left-hand side toolbar, click on the Home icon.

  6. In HPE Aruba Networking Central, click on the Config tab in the top-right corner.

  7. In the left-hand side menu, click on the Sites option, and then click on the name of your site.

  8. On the Profiles tab, in the Profiles Management pane, click on the Authentication Server entry in the Security card.

  9. Click on the Create Profile button to create a new authentication server profile.

  10. Configure the new authentication server profile:

    1. In the Name field, enter a name for this server.
    2. Activate the Secure RADIUS checkbox, and leave the RADIUS option selected in the Auth Server Mode field.
    3. In the IP Address/FQDN field, enter the FQDN (fully qualified domain name) of the Portnox Cloud RADIUS server, not its IP address.
      Warning:
      If you use the IP address, this configuration will not work.

      To find the FQDN of your Cloud RADIUS server, see the following topic: What are the fully qualified domain names (FQDNs) of Cloud RADIUS servers.

    4. In the Secure Authentication Port field, enter the Authentication port value from Portnox Cloud.
    5. In the Certificate Type field, leave the Internal option selected.
    6. In the Secure RADIUS Trusted CA field, select the root certificate that you uploaded earlier.
    7. Click on the Create button.
  11. If you use Cloud RADIUS servers in both regions, repeat the above two steps for the second RADIUS server.
  12. Create a separate authentication server group that contains only the RadSec server profiles, as described in the previous section: Create RADIUS server profiles.

Result: You created an authentication server group for RadSec. When you configure an SSID, select this group in the Server Group field instead of the non-RadSec group.

Optional: Configure mutual authentication (mTLS)

In this section, you will create a client certificate for the access point and configure Portnox Cloud to verify it during the RadSec connection.

Important:
Before you begin, you must complete the previous section: Create RadSec server profiles.
Warning:
If you configure Portnox Cloud for mTLS authentication, all your NAS devices that use RadSec with the same Cloud RADIUS instance must be configured for mTLS.
  1. Make sure that OpenSSL is installed on your computer.

    OpenSSL is a free command-line tool for creating and managing certificates and keys. Most Linux distributions include OpenSSL by default. macOS includes a compatible openssl command. Windows does not include OpenSSL, but you can use it in Windows Subsystem for Linux (WSL), which includes OpenSSL in its default Ubuntu distribution.

    To check if OpenSSL is installed, open a command prompt or a terminal, and run the following command:

    openssl version

    If the system does not find the command, install OpenSSL:

    • On Linux, install the openssl package using the package manager of your distribution.

    • On Windows, install a third-party binary distribution. For a list of distributions, see the following page: https://github.com/openssl/openssl/wiki/Binaries. Git for Windows also includes OpenSSL, which you can use in Git Bash.

  2. Open a command prompt or a terminal, and run the following OpenSSL commands:
    openssl req -x509 -newkey rsa:2048 -sha256 -days 3650 -nodes -keyout aruba-client-ca.key -out aruba-client-ca.crt -subj "/CN=aruba-client-ca"
    openssl req -newkey rsa:2048 -sha256 -nodes -keyout aruba-client.key -out aruba-client.csr -subj "/CN=aruba-client"
    echo basicConstraints = CA:FALSE> aruba-client.ext
    echo keyUsage = digitalSignature, keyEncipherment>> aruba-client.ext
    echo extendedKeyUsage = clientAuth>> aruba-client.ext
    openssl x509 -req -in aruba-client.csr -CA aruba-client-ca.crt -CAkey aruba-client-ca.key -CAcreateserial -out aruba-client.crt -days 825 -sha256 -extfile aruba-client.ext
    openssl pkcs12 -export -out aruba-client.pfx -inkey aruba-client.key -in aruba-client.crt -certfile aruba-client-ca.crt -name aruba-client

    These commands create your own certificate authority and use it to sign a client certificate for the access point. You need two of the resulting files:

    • aruba-client-ca.crt: the certificate authority, which you upload to Portnox Cloud.

    • aruba-client.pfx: the client certificate, which you upload to HPE Aruba Networking Central.

    When prompted, enter an export password. You need this password when you upload the aruba-client.pfx file to HPE Aruba Networking Central.

    Important:
    Keep the aruba-client-ca.key file in a secure location. Anyone with this file can issue certificates that Portnox Cloud trusts.
  3. In HPE Aruba Networking Central, in the left-hand side toolbar, click on the Menu icon.

  4. Click on the Manage button in the Certificate Management card.

  5. Click on the Add button to add a new certificate.

  6. Upload the client certificate:

    1. In the Name field, enter a name for the certificate.
    2. In the Type field, select the Client option.
    3. In the Format field, select the PKCS12 option.
    4. In the Password and Confirm Password fields, enter the export password that you set earlier.
    5. In the Upload Certificate field, click on the Select File button, and select the aruba-client.pfx file.
    6. Click on the Add button.
  7. In HPE Aruba Networking Central, in the left-hand side toolbar, click on the Home icon.

  8. In HPE Aruba Networking Central, click on the Config tab in the top-right corner.

  9. In the left-hand side menu, click on the Sites option, and then click on the name of your site.

  10. On the Profiles tab, in the Profiles Management pane, click on the Certificate Usage entry in the Security card.

    Note:
    If you do not see this entry, click on the second circle icon in the card to go to its second page.
  11. Click on the Create Profile button to create a new certificate usage profile.

  12. Configure the new certificate usage profile:

    1. In the Name field, enter a name for this profile.
    2. In the Device Type field, leave the Access Point option selected.
    3. In the RadSec Server CA field, select the Cloud RADIUS root certificate that you uploaded earlier.
    4. In the RadSec Client Certificate field, select the client certificate that you uploaded earlier.
    5. Leave the remaining fields at their default values, and click on the Create button.
  13. In Portnox Cloud, go to Settings > Services > GENERAL SETTINGS > Trusted Root Certificates, and upload the aruba-client-ca.crt file.

  14. Go to Settings > Services > CLOUD RADIUS SERVICE > Cloud RADIUS instance, select the relevant RADIUS instance, select  ⋮  > Edit, activate the Validate NAS Client Certificate (RadSec) option, and click on the Save button.

    Important:
    Complete this step only after HPE Aruba Networking Central has pushed the new configuration to the access point. Otherwise, the RadSec connection fails until the access point receives the client certificate.

Result: The access point and Portnox Cloud authenticate each other when the access point connects using RadSec. SSIDs that use the RadSec server group need no changes. They start using mutual authentication as soon as you save the Portnox Cloud setting.

Create an SSID for 802.1X authentication

In this section, you will create a WLAN profile and configure it for WPA2 Enterprise authentication, using the authentication server group that you created earlier.

  1. In HPE Aruba Networking Central, click on the Config tab in the top-right corner.

  2. In the left-hand side menu, click on the Sites option, and then click on the name of your site.

  3. On the Profiles tab, in the Profiles Management pane, click on the WLAN entry in the Wireless card.

  4. Click on the Add WLAN button to create a new WLAN profile.

  5. In the General section, in the Name field, enter a display name for this profile, and in the ESSID Name field, enter the network name that devices see when they search for Wi-Fi networks.

  6. In the Security section:

    1. In the Security Level field, select the Enterprise option.
    2. In the Key Management field, select the WPA2-Enterprise option.
      Note:
      You can also select one of the WPA3-Enterprise options or the Both option instead. The authentication configuration is identical. The only difference is the supported Bands and Wi-Fi Protocols.
    3. In the Server Group field, select the authentication server group that you created earlier.
      Note:
      To use RadSec, select the RadSec server group instead.
    4. Leave the Perform MAC Authentication Before 802.1X and MAC Authentication Fall-Through checkboxes cleared.
      Note:
      If you select Perform MAC Authentication Before 802.1X, the access point first sends a MAC authentication request for each device to Portnox Cloud. Portnox Cloud rejects devices that do not have a MAC-based account. The access point does not start 802.1X authentication for these devices, so they cannot connect. If you select MAC Authentication Fall-Through, 802.1X authentication starts even after a failed MAC authentication. However, each connection then sends an extra MAC authentication request to Portnox Cloud, causing a failed MAC authentication alert. Therefore, create a separate SSID to support MAC Address Bypass (see below).
    5. In the Accounting field, select the Use Server Group option.
  7. Leave the remaining settings at their default values unless your environment requires otherwise, and click on the Create button.

Result: You created an SSID that authenticates employee Wi-Fi devices using 802.1X and the Portnox Cloud RADIUS servers.

Optional: Create an SSID for MAC-based authentication

This is an optional task. Follow this task only if you want to authenticate devices, such as IoT devices, that do not support 802.1X, using their MAC address instead.

  1. In HPE Aruba Networking Central, click on the Config tab in the top-right corner.

  2. In the left-hand side menu, click on the Sites option, and then click on the name of your site.

  3. On the Profiles tab, in the Profiles Management pane, click on the WLAN entry in the Wireless card.

  4. Click on the Add WLAN button to create a new WLAN profile.

  5. In the General section, in the Name field, enter a display name for this profile, and in the ESSID Name field, enter the network name that devices see when they search for Wi-Fi networks. Then, in the Bands section, deactivate the 6 GHz checkbox and in the Wi-Fi Protocols section, deactivate the Wi-Fi 7 (802.11be) checkbox.

    Note:
    If 6 GHz is selected in the Bands section or if Wi-Fi 7 (802.11be) is selected in the Wi-Fi Protocols section, the Open option is not available in the Key Management field.
  6. In the Security section:

    1. In the Security Level field, select the Open option.
    2. In the Key Management field, select the Open option.
    3. In the Authentication section, activate the MAC Authentication checkbox.
    4. In the Server Group field, select the authentication server group that you created earlier.
      Note:
      To use RadSec, select the RadSec server group instead.
    5. In the Accounting field, select the Use Server Group option.
  7. Leave the remaining settings at their default values unless your environment requires otherwise, and click on the Create button.

Result: You created a separate SSID that authenticates IoT devices by their MAC address using the Portnox Cloud RADIUS servers on the basis of MAC-based accounts.

Optional: Create an SSID for IPSK authentication

This is an optional task. Follow this task only if you want to authenticate devices using RADIUS-based identity pre-shared keys (IPSK). HPE Aruba Networking Central calls this feature MPSK (Multi Pre-Shared Key).

For more information about IPSK in Portnox Cloud, see the following topic: Create a MAC-based account.

Important:
You cannot use the same SSID for both WPA2/WPA3 Enterprise authentication and IPSK authentication. Create a separate SSID for IPSK.
  1. In HPE Aruba Networking Central, click on the Config tab in the top-right corner.

  2. In the left-hand side menu, click on the Sites option, and then click on the name of your site.

  3. On the Profiles tab, in the Profiles Management pane, click on the WLAN entry in the Wireless card.

  4. Click on the Add WLAN button to create a new WLAN profile.

  5. In the General section, in the Name field, enter a display name for this profile, and in the ESSID Name field, enter the network name that devices see when they search for Wi-Fi networks. Then, in the Bands section, deactivate the 6 GHz checkbox and in the Wi-Fi Protocols section, deactivate the Wi-Fi 7 (802.11be) checkbox.

    Note:
    If 6 GHz is selected in the Bands section or if Wi-Fi 7 (802.11be) is selected in the Wi-Fi Protocols section, the MPSK AES option is not available in the Key Management field.
  6. In the Security section:

    1. In the Security Level field, select the Personal option.
    2. In the Key Management field, select the MPSK AES option.
    3. In the Server Group field, select the authentication server group that you created earlier.
      Note:
      To use RadSec, select the RadSec server group instead.
    4. In the Accounting field, select the Use Server Group option.
  7. Leave the remaining settings at their default values unless your environment requires otherwise, and click on the Create button.

Result: You created a separate SSID that authenticates devices using identity pre-shared keys from Portnox Cloud.

Legacy solutions

Classic Central WPA2 Enterprise

In this section, you will learn how to configure access points managed using Aruba Central to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections.

Note:
This configuration was tested using the Aruba AP-505 Access Point.
  1. In the left-hand side main menu, click on the Devices option and then, in the right-hand side pane, click on the name of the device that you want to configure.

  2. In the left-hand side menu for the selected device, click on the Device option. Then, in the right-hand side pane, make sure that the WLANs tab is active, and under the Wireless SSIDs list, click on the Add SSID button to add a new SSID.

    Note:
    You can also edit an existing SSID by clicking on its name on the Wireless SSIDs list.
  3. In the Create a New Network wizard, fill in the fields as required for your new SSID until you get to the Security step.
  4. In the Security step:

    1. Set the Security Level slider to the Enterprise position.
    2. In the Key Management field, select the preferred key management protocol.
    3. Click on the  +  icon to the right of the Primary Server label to create a RADIUS server configuration.
  5. In the New Server window:

    1. In the Server Type field, select the RADIUS option.
    2. In the Name field, enter a name for this RADIUS server configuration.
    3. In the IP Address/FQDN field, enter your Cloud RADIUS IP, which you obtained when you created the Cloud RADIUS server.
    4. In the Shared Key and Retype Key fields, paste your Shared Secret, also obtained when you created the Cloud RADIUS server.
    5. In the Auth Port field, enter your Authentication port number, also obtained when you created the Cloud RADIUS server.
    6. In the Accounting Port field, enter your Accounting port number, also obtained when you created the Cloud RADIUS server.
    7. In the Timeout (in secs) field, enter 30 to avoid timeouts due to any intermittent Internet connection delays.
    8. Click on the OK button to save your configuration.
  6. Optional: Back in the Create a New Network wizard’s Security step, click on the  +  icon to the right of the Secondary Server label to create a second RADIUS server configuration.

    Note:
    Do this only if your Portnox Cloud tenant is configured with two Cloud RADIUS servers or if you’re using a local RADIUS server in addition to the Cloud RADIUS server.
  7. Complete the remaining steps of the Create a New Network wizard.

Classic Central Identity PSK (IPSK)

In this section, you will learn how to configure access points managed using Aruba Central to work together with Portnox™ Cloud and RADIUS-based identity pre-shared key (IPSK) authentication for Wi-Fi connections.

For more information about IPSK in Portnox Cloud, see the following topic: Create a MAC-based account.

  1. In the left-hand side main menu, click on the Devices option and then, in the right-hand side pane, click on the name of the device that you want to configure.

  2. In the left-hand side menu for the selected device, click on the Device option. Then, in the right-hand side pane, make sure that the WLANs tab is active, and under the Wireless SSIDs list, click on the Add SSID button to add a new SSID.
    Important:
    You cannot use the same SSID for both WPA2/WPA3 Enterprise authentication and IPSK authentication, so you need to create separate SSIDs.

    Note:
    You can also edit an existing SSID by clicking on its name on the Wireless SSIDs list.
  3. In the Create a New Network wizard, fill in the fields as required for your new SSID until you get to the Security step.
  4. In the Security step:

    1. Set the Security Level slider to the Personal position.
    2. In the Key Management field, select the MPSK AES protocol.
    3. Click on the  +  icon to the right of the Primary Server label to create a RADIUS server configuration.
      Note:
      If you already added RADIUS servers for a different SSID based on 802.1X authentication (previous section of this topic), do not click the  +  icon, skip the next step (creating RADIUS servers), select an existing server in the Primary Server field, and then select the other existing server in the Secondary Server field that appears.
  5. In the New Server window:

    1. In the Server Type field, select the RADIUS option.
    2. In the Name field, enter a name for this RADIUS server configuration.
    3. In the IP Address/FQDN field, enter your Cloud RADIUS IP, which you obtained when you created the Cloud RADIUS server.
    4. In the Shared Key and Retype Key fields, paste your Shared Secret, also obtained when you created the Cloud RADIUS server.
    5. In the Auth Port field, enter your Authentication port number, also obtained when you created the Cloud RADIUS server.
    6. In the Accounting Port field, enter your Accounting port number, also obtained when you created the Cloud RADIUS server.
    7. In the Timeout (in secs) field, enter 30 to avoid timeouts due to any intermittent Internet connection delays.
    8. Click on the OK button to save your configuration.
  6. Optional: Back in the Create a New Network wizard’s Security step, click on the  +  icon to the right of the Secondary Server label to create a second RADIUS server configuration.

    Note:
    Do this only if your Portnox Cloud tenant is configured with two Cloud RADIUS servers or if you’re using a local RADIUS server in addition to the Cloud RADIUS server.
  7. Complete the remaining steps of the Create a New Network wizard.

Aruba 7000 Series

In this section, you will learn how to configure Aruba 7000 series of controllers with the ArubaOS operating system to work together with Portnox™ Cloud and 802.1X RADIUS authentication for Wi-Fi connections.

Warning:
This topic contains documentation prepared by our support agents more than 12 months ago. It may not cover the newest models or the newest interfaces of NAS devices. We’re working on bringing you updated documentation for NAS devices in the near future. However, the methods of setting up third-party devices may still change when the manufacturers update their firmware or release new models.
  1. In the Aruba web interface, navigate to Configuration > Wizards > Campus WLAN, and add a new SSID or select an existing one.

  2. In the Internal/Guest section, select Internal.

  3. In the Authentication and Encryption section, select Strong encryption with 802.1x authentication.

  4. In the Authentication Server section, add a new server.

    1. In Server type, select RADIUS.
    2. Enter your Cloud RADIUS details.
  5. Navigate to Configuration > Security > Authentication > Servers, select the RADIUS server that you created in the previous step, and update the Timeout to 30 seconds.

  6. Click on Save Configuration.