Onboarding devices using Aruba Onboard
6 minute read
End-user device Onboarding
Employee devices can easily be configured for seamless connection to wired and wireless networks. Managed through HPE Aruba Networking Central, end users are authenticated through cloud identity stores with an enrollment link provided by HPE Aruba Networking Central. The user will be redirected to the identity store for authentication and log in.
Client devices can be configured using HPE Aruba Networking Onboard, a client app that installs wired / wireless network profile on the client device. With the profile installed, anytime the user walks into range of the network, the client device will automatically connect with the appropriate network access rules as configured by the admin through HPE Aruba Networking Central.
HPE Aruba Networking Onboard provides automatic renewals, requiring no additional onboarding steps and upkeep from the end user, while allowing the admin to change and update policies at any time. It is supported on macOS, Windows, iOS, and Android operating systems.
Onboarding workflow
Central NAC policies in Aruba Central define a set of rules and authorize users and devices to access networks. Users can authenticate through cloud identity providers like Microsoft Entra ID, Okta or Google Workspace, and download network profiles to access enterprise wireless network. After downloading the network profiles, your devices can connect automatically to the enterprise wireless network.
The following workflow shows the steps required to connect wireless devices to the network using Central NAC.
Onboarding starts from a provisioning page which takes the end users to a login page associated with the identity source configured in Central NAC. There are several different ways to distribute the onboarding URL depending upon the environment. Using QR codes is one easy and user friendly way if the goal is to onboard smart phone and similar devices that can scan a QR code. If you have a guest network with a captive portal page, the onboarding URL can be embedded in the captive portal page as well. You could also add the onboarding URL to an FAQ page on your organization’s internal portal.
The provisioning page is publicly accessible and hence onboarding can be done outside of corporate network. This, for example enables remote employees receiving new devices to onboard from their home network without having to connect to a VPN or corporate managed network.
INFO
The following operating systems support onboarding using the Aruba Onboard App:
- Windows 10 version 1803 or later versions
- Windows Server 2016 or later versions
- Android 9 or later versions
- macOS 10.13 or later versions
- iOS 12.1 or later versions
WARNING
The iOS 15.0 and iOS 15.1 versions are not supported because of a bug in iOS. The iOS 15.2 version is supported.
Prerequisites for Onboarding
-
Ensure that you have the onboarding URL shared by the network administrator. The onboarding URL is used to connect your device to wireless network using Central NAC. You should also obtain your Microsoft Entra ID / Google Workspace / Okta credentials from your network administrator to authenticate using the URL.
-
On Windows devices, ensure that the Wi-Fi adapter is enabled to install the network profiles and connect to the network
-
For better UI rendering experience on laptop devices, ensure the screen resolution is 1920x1080 (Full HD/1080p).
Aruba Onboard Sample Videos
iPhone Onboarding
iPad Onboarding
Android Onboarding
Windows 11 Onboarding
Chromebook Onboarding
Onboarding FAQs
Q: What is the lifetime of client certificates generated through the onboarding process?
A: If using Cloud Auth and Policy in HPE Aruba Networking Central classic, the client certificate lifetime is 1 year. With Central NAC in New Central, the lifetime can be configured to be either 90 days / 180 days / 365 days
Q: How does certificate renewal work with Aruba Onboard App?
A: Onboard App notifies the user when a certificate is about to expire and prompts the user to renew the certificate. Expiration notification gets triggered when the certificate is at 80% of its lifetime.
Q: What happens when the client changes their password on the cloud based identity provider after onboarding and installing the network profile? Do the clients have to repeat the onboarding process and install a new network profile?
A: There is no impact to the onboarded device even if the user changes their Entra ID password. Once the profile is installed, the certificate within the profile is used for authentication. The device will still be able to connect to the SSID mentioned in the network profile using the certificate. It can also do a profile refresh successfully. If the user deletes the profile, only then they will need to use the new Entra ID password to login to the onboarding page to be able to download the network profile.
Q: What happens if a customer hits Cloud Identity Provider API limits?
A: Central NAC use API calls to fetch user information from Cloud Identity sources. Care must be taken that API limits are appropriately so that user authentications are not impacted.
Q: How does Aruba Onboard app handle the scenario where a USB ethernet dongle is plugged into wired port of a laptop.
A: Aruba Onboard app would install the network profile on the laptop and it would be able to authenticate successfully and connect to the network. Even if the laptop later uses a different USD ethernet dongle, the device would be still be able to connect to network since the certificate would remain the same.
Q: What certificates does Central NAC use?
A: Every Central NAC account or tenant comes with a unique root and intermediate (signing) certificate authority certificates which are used to issue certificate to onboarded devices. This is a private CA that is managed automatically by Central NAC.
Q: How to renew client certificates. Is the update only possible if the device is not in shutdown or deep sleep mode at the moment of the update?
When client certificates reach 80% of its lifetime, the Onboard app would generate a notification that the ceritficate is about to expire. User has to then open the app to renew the certificate.
Q: Private Root CA expiration - Is the client certificate automatically renewed when the private root CA expires?
A: The private CA would be renewed automatically prior to the expiration. This ensures that the client certificates will continue to work without having to renew.
Q: Central Upgrade. Does Central NAC authentication become unavailable while Central is upgrading?
A: Central NAC would continue to authenticate users even if Aruba Central is down or undergoing maintenance.
Q: If the identity source is out of service, can clients continue to authenticate?
A: Onboarding new devices requires authentication against the identity source and hence would not be possible. Existing devices that already have a profile installed will be able to authenticate successfully. If there was any changes made to the group membership of the user, those changes would only be read by Central NAC once the service is restored. So authorization would use the last known group memberships.
Q: How long does the certificate renewal take
Just as Onboarding takes only few seconds to complete, renewal also completes very quicky.
Feedback
Was this page helpful?
Glad to hear it!
Sorry to hear that.