Visitor access workflows

This section covers the visitor management workflows in Central NAC

The visitor management feature allows visitors to connect to the network and at the same time, allows the administrator to control visitor access to the network.

HPE Aruba Networking Central allows administrators to create a splash page for visitors. For example, you can create a splash page that displays a corporate logo, color scheme and the terms of service, and enable logging in from a social networking service such as Facebook, Google, Twitter, and LinkedIn.

Guest operators can also create visitor accounts. For example, a network administrator can create a guest operator account for a receptionist. The receptionist creates accounts for visitors who require temporary access to the wireless network. Guest operators can create and set an expiration time for visitor accounts. For example, the expiration time can be set to 1 day.

To enable logging using Facebook, Google, X, and LinkedIn credentials, ensure that you create an application (app) on the social networking service provider site and enable authentication for that app. The social networking service provider will then issue a client ID and client secret key that are required for configuring guest profiles based on social logins.

Central NAC supports the following visitor workflows:

  • Anonymous login: Login without any username or password
  • Static password based login: Login with a common shared password
  • Captive portal login using cloud identity (Google Workspace, Okta, Microsoft Entra ID)
  • Visitor login using social media accounts (Facebook, Google Social, LinkedIn, X)
  • Visitor login using any Open ID Connect (OIDC) identity provider
  • Visitor registration: Register for an account and login
  • Visitor registration with verification: Register for an account and verify phone number / email by using a verification code or link
  • Visitor registration with sponsor approval: Register for an account and have a sponsor approve it
  • MAC Caching with all of the above scenarios to avoid repeated logins

Configuring Visitor Workflows

THe high level steps to configure a WLAN for visitor access are:

  1. Configure a WLAN for visitor access with the captive portal type set to Central NAC
  2. Configure Authentication Profile to define the visitor workflow
  3. Configure Themes to define the look and feel of the visitor portal
  4. Configure Override profiles for overriding default labels
  5. Upload images to be used in the visitor portal
  6. Configure portal profile and select the theme and override profile to be used with the splash page

Configuring WLAN for Visitor access

Create a WLAN with the captive portal set to Central NAC as shown below. Optionally you can configure the WLAN to use enhnanced open for additional security.



Configuring WLAN
Configuring WLAN


Configuring Authentication Profile

Navigate to Central NAC > Configuration > Authentication Profiles and create a new profile for visitor access. Set the authentication type to “Captive Portal” and select the WLAN that was created earlier under the “Network” drop down.



Configuring Authentication Profile
Configuring Authentication Profile


Under the section “Authentication” are all the options related to configuring the visitor access workflows. You can choose between anonymous logins or logins based on registered visitor accounts, enable sponsorship approval, restrict sponsor domains and specify static sponsor email or delivery lists.



Configuring Authentication Profile
Configuring Authentication Profile


The “Default Policy” section allows you to configure MAC Caching and to enable session restrictions



Configuring Default Policy
Configuring Default Policy


The portal customization selection is to select a portal profile which determines the look and feel of the visitor captive portal page. Leave this blank initially. Once the theme, override and portal profiles have been created, the authentication profile can be updated with the name of the portal profile.



Selecting the Portal Profile
Selecting the Portal Profile


Designing the Visitor portal

Central NAC allows limited customization of the visitor portal with ability to use custom color scheme, background images and icons.



Sample Visitor Portal
Sample Visitor Portal


To create a visitor portal, navigate to Central NAC > Configuration > Portal Customization > Themes and create a new Theme to design the look and feel of the visitor portal. Use this page to select the color scheme, select background image and favicon images.

The text and labels on the portal can be modified by using the Override Profile. This profile allows you to select languages and to apply a message override to match exactly what you are looking for. Some of the fields accept HTML inputs and can be used for more advanced customizations. For example, the “Login Message” can be customized to add specific instructions for the visitors. The tool tip for the field override would indicate whether the field accepts “Basic HTML” input or not as shown below:



Using custom HTML as field override
Using custom HTML as field override


INFO

Note that only simple HTML without the head or body HTML tags can be used within the overrides. CSS or javascript is also not supported in the field overrides

Page background, Sign In and favicon images can be uploaded under the Images card

The Portal Profile is used to combine all of the other design elements by combining theme and override profile along with images. Once the portal profile has been created, you can reference it under the Authentication Profile

Visitor Store

Central NAC supports multiple visitor stores. This helps with scenarios where visitor accounts are local to specific sites or networks. For example, ACME Enterprises has self registration for any visitors to their corporate HQ and also has helpdesk create visitor accounts for contractors who visit their branches. These two sets of accounts can be stored in different stores and assigned different levels of access based on which store they are part of.

Visitor accounts can be accessed from Central NAC > Configuration > Visitors. While adding new visitors, you can select the appropriate visitor store or create a new one from the Visitor Store drop down.



Creating Visitor Account
Creating Visitor Account






Central Guest Operator

Central also supports restricted access for operators to create visitor accounts. Users can be assigned the “Aruba Central Guest Operator” role either statically or through SAML SSO which would limit them to create and manage visitor accounts only. Other Central NAC configuration screens hidden and the dashboards would be empty.



Guest Operator Access
Guest Operator Access


Satic assignment of roles is done from Greenlake Workspace Management > Workspace identity and access > Users



Guest Operator Role Assignment
Guest Operator Role Assignment


Steps to configure SAML SSO for Aruba Central and HPE Greenlake is documented here:

https://developer.hpe.com/blog/okta-sso-integration-for-green-lake-and-aruba-central/

Central NAC Visitor FAQs

Q: Does visitors count towards NAC subscription?

A: Standard visitor workflows are included as part of the core capabilities and does not require a NAC subscription. Reference for core vs subscription capabilities: https://arubanetworking.hpe.com/techdocs/NAC/central-nac/central-nac-understanding-foundation-vs-advanced-subscriptions/

However if NAC subscription is applied to enable any of the subscription capabilities, all authenticated sessions including visitors, clients and users count towards the NAC subscription

Q: Is there a limit to number of visitor accounts and visitor stores that can be added?

A: No, there is no hard limit on the number of visitor accounts or stores


Last modified: April 3, 2026 (4c77354a)