Air Pass in Central NAC
8 minute read
Air Pass offers a seamless roaming solution for devices to connect to the enterprise networks based on Passpoint / Hotspot 2.0 specifications.
Air Pass module offers two different services:
-
Air Pass - SIM is a roaming service designed to enable MNOs to extend their 5G cellular coverage and automatically roam on enterprise networks powered by HPE Aruba Networking gear. Devices with supported MNOs automatically connect to Air Pass SIM Wi-Fi network using the credentials embedded in the SIM card.
-
Air Pass - OpenRoaming adds support for the global Wi-Fi roaming standard developed by Wireless Broadband Alliance (WBA). While Air Pass - SIM only works for devices with a SIM card, OpenRoaming works for wide range of devices both with and without SIM cards and allows devices to connect to Open Roaming Wi-Fi hotspots across the world.
Air Pass - SIM
Some key use case with Air Pass - SIM is:
- Provides frictionless onboarding of guest devices to Wi-Fi without going through the captive portal.
- It is beneficial at places like schools, universities, hotels, retail stores, hospitals, and other indoor venues that provide enterprise Wi-Fi hotspots.
- With Air Pass, mobile users enjoy seamless and secure guest access to Wi-Fi networks in the enterprise venues.
- Empowers the enterprise Wi-Fi networks to serve as full-fledged roaming partners to the mobile operator’s 5G networks and in turn, allows the mobile operators to rely upon the enterprise Wi-Fi networks as a cost-effective extension of their own 5G coverage.
- Enables 5G experience with Wi-Fi 5/6/6E/7
- Provides seamless transition and authentication of 4G and 5G users to Wi-Fi networks.
- Provides role-based control and simplified device onboarding using enterprise security.
- Uses WPA2 and WPA3 Enterprise wireless security.
- Enables cellular roaming in the existing Wi-Fi network without hardware upgrades or DAS systems
How does it work?
Air Pass SIM uses the Passpoint profiles provisioned by MNOs on the SIM-enabled devices of their subscribers. While traditional Passpoint technology requires each organization to establish roaming agreements with MNOs directly, Air Pass SIM allows customers to deploy Passpoint using the agreements established by HPE with the supported MNOs.
Central NAC Air Pass - SIM authentication workflow
-
After receiving an authentication request from a guest user to connect to a WLAN network, Central NAC proxies the authentication request to the MNOs.
-
The MNOs validate and respond to the authentication request.
-
If the authentication request is passed successfully by the MNO, Central NAC then configures a role-based policy to provide guest access to the WLAN network.
TIP
Air Pass - SIM officially supports devices with AT&T (including MVNOs Cricket Wireless, AT&T Mobility and FirstNet) and T-Mobile SIM cards. Whether a device can use Passpoint / Hotspot 2.0 technology is at the discretion of the MNO. Depending upon device model and cellular plan, MNO have the option to provision Passpoint profiles or not.
INFO
Air Pass is a function of Classic Central that is only available for use in the United States. Usage of Air Pass outside of the United States may subject you to additional liability, and you acknowledge that risk through your use of Air Pass. Terms and conditions associated with Air Pass may be found on https://www.arubanetworks.com/legal/, and may be updated at HPE’s sole discretion from time to time. All devices auto-connect to Air Pass SSID. However, the following devices fail to connect automatically:
- Pixel running Android 10
- Pixel running Android 11
- Pixel running Android 12
WARNING
Devices with FirstNet will not auto connect to Passpoint / Hotspot 2.0 networks including Air Pass. FirstNet users will need to manually select the Air Pass SSID from the Wi-Fi picker during the initial connection. Once connected, the device will automatically reconnect to the SSID whenever it is available.
INFO
Air Pass service is offered as part of the foundation capabilities in HPE Networking Aruba Central.
Configuring Air Pass on New Central
Air Pass uses 802.1X EAP-SIM / EAP-AKA authentication for the WLAN which can be configured to be either in bridged or tunneled mode. The high level configuration steps are:
- Create a WLAN as shown below:
- Air Pass is enabled on a per site basis so the WLAN needs to be assigned to an appropriate site scope.
INFO
Note that for tunneled SSID, the WLAN needs to be assigned to “Device Group” scope first and then the appropriate site.
- Create a new Air Pass profile from Central NAC > Air Pass > Air Pass Profile. Select the carriers you wish to enable and the sites.
Select appropriate providers, followed by the network created earlier and select the sites where Air Pass needs to be enabled. For customer domain name, enter the domain name of your organization and select appropriate venue category for your organization.
Once the profile is created, an approval email is triggered to HPE Networking Central NAC team. You will receive an email acknowledging the receipt of the approval request. The requests are sent to MNOs for approval and the process could take up to 30 days to complete.
Once the request is approved, an approval email will be sent to the provided email address. At this point, the WLAN and the passpoint related profiles are enabled and devices should be able to start connecting as soon as the request is approved.
INFO
In New Central, changing the name of Air Pass WLAN will again trigger approvals and the approval status will revert back to pending until the approval is processed.
Creating Passpoint profiles manually and assigning to the same sites as the Air Pass WLAN will cause Air Pass profiles to be overwritten and approvals to be re-done.
Air Pass - OpenRoaming
OpenRoaming standard brings together a federation of networks and identity providers, allowing users to join any network managed by a federation member.
Companies who join OpenRoaming provide assurance that their Wi-Fi networks automatically interoperate between each other to deliver an automatic and secure connected Wi-Fi experience.
WBA OpenRoaming enables companies to accelerate and scale Wi-Fi roaming relationships. Enabled networks can automatically onboard users securely leveraging established identity providers such as operators, cloud IDs, loyalty membership, bridging the gap between Wi-Fi and cellular networks.
Some key use cases with Air Pass - OpenRoaming is:
- Globally available federation of networks that allow users to seamlessly connect to different venues like airports, hotels and resorts, stadiums and event venues, smart cities, retail and shopping malls
- Provides frictionless connection without having to go through captive portals
- Allows elevated Wi-Fi connectivity experience for loyalty customers through Apps
- Provides seamless transition and authentication of 4G and 5G users to Wi-Fi networks (with MNOs that support OpenRoaming)
How does it work?
With OpenRoaming, authentication can happen either using the OpenRoaming profiles provisioned by MNOs on subscriber devices or by having the users go through a one time onboarding process. For scenarios involving loyalty apps like the ones commonly used by retail / hospitality / event management services, the App can do the onboarding silently for end users.
Google Pixel and Samsung devices natively support OpenRoaming onboarding. When users select the OpenRoaming SSID, these devices would request users to sign in using their Google / Samsung credentials and install an OpenRoaming profile. Apple does not support native onboarding and hence must use either App based or web based onboarding methods.
Once the OpenRoaming profile has been installed, the devices will automatically connect to any OpenRoaming enabled Wi-Fi network across the world.
Central NAC Air Pass - OpenRoaming authentication workflow
-
After receiving an authentication request from a user to connect to a Air Pass - OpenRoaming network, Central NAC extracts the domain name part of the username which is tied to the IDP used while doing the initial onboarding. Example anonymous@apple.openroaming.net for a user who onboarded using their Apple credentials
-
Central NAC does a dynamic DNS NAPTR lookup with the domain name to find the AAA servers associated with the IDP. DNS NAPTR response would include details about the AAA server and other information like whether it supports RadSec or not
-
Central NAC establishes RadSec connection to the IDP using the WBA issued PKI
-
The IDPs validate and respond to the authentication request.
-
If the authentication request is passed successfully by the IDP, Central NAC then configures a role-based policy to provide access to the WLAN
INFO
Central NAC only support settlement free version of OpenRoaming where there are on fees involved for roaming between venues.
Configuring OpenRoaming in New Central
Air Pass uses 802.1X EAP-SIM / EAP-AKA authentication for the WLAN which can be configured to be either in bridged or tunneled mode. The high level configuration steps are:
- Create a WLAN as shown below:
- Air Pass is enabled on a per site basis so the WLAN needs to be assigned to an appropriate site scope.
INFO
Note that for tunneled SSID, the WLAN needs to be assigned to “Device Group” scope first and then the appropriate site.
- Create a new Air Pass profile from Central NAC > Air Pass > Air Pass Profile. Select the provider as “OpenRoaming (All)” followed by the network created earlier and select the sites where OpenRoaming needs to be enabled. For customer domain name, enter the domain name of your organization and select appropriate venue category for your organization.
There is no approval required for OpenRoaming. With this, the OpenRoaming network is ready to use.
Feedback
Was this page helpful?
Glad to hear it!
Sorry to hear that.