AOS-10 APs and Mobility Gateways Configuration

This section provides an overview of the AOS-10 APs and Mobility Gateways configuration and operations journey.

Important:
  • Automatic configuration migration from Classic Central group to HPE Aruba Networking Central group is currently not supported.

  • You must create tunnel-mode WLAN profiles in the Library and assign them to the device groups containing the APs that service the ESSID.

    • Future updates will add support to assign WLAN profiles to any scope in the hierarchy, including Global, Site Collections, Sites, Devices, and Device Groups.

The following image displays the high-level steps to deploy and configure AOS-10 APs and Mobility Gateways.

Figure 1: AOS-10 AP and Mobility Gateways Configuration and Operations

The following sections describe the first four steps displayed in AOS-10 AP and Mobility Gateways Configuration and Operations

Step 1—Configuring AOS-10 APs

The following image displays the steps to configure AOS-10 APs on the network.

Figure 2: AOS-10 AP-only Configuration Steps

To configure the AOS-10 APs and get the clients connected over wireless network, complete the following steps:

  1. Setting the User Administrator Password for AOS-10 APs

  2. Configuring VLAN Profile

  3. Configuring AP System Profile

  4. Configuring AP Uplink Port Profile

Setting the User Administrator Password for AOS-10 APs

You can edit the default user administrator profile for Campus Access Points to set your own password.

Note:

The user administrator is an optional setup for user management.

To configure the user administrator password, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select Global.

  3. Under Profiles Management page on the right, select Campus Access Point from the Device Function drop-down list.

  4. On the System card, click User Administration.

    Figure 3: User Administrator Profile Option

    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the User Administration card, click Manage.

    The User Administration list view is displayed.

  5. Click anywhere on the row of the existing administrator profile in the list view.

    The Edit Profile side panel is displayed.

  6. Under Password and Retype Password, enter the same password.

  7. From the Role drop-down list, select Admin.

  8. Click Update.

    Figure 4: User Administration Profile Configuration

    The new password is assigned to the user administrator.

    For more information, see User Administration Profile.

Configuring VLAN Profile

To configure VLAN profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select Library.

  3. On the VLANs & Networks card, click VLAN.

    Figure 5: VLAN Profile Option


    Alternatively, you can complete the following steps:

    1. On the VLANs & Networks card, click Manage.

    2. On the VLAN card, click Manage.

    The VLAN list view is displayed.

  4. Click Create Profile.

  5. In the Create Profile side panel, configure the following VLAN profile parameters:

    • VLAN ID—Enter the numeric VLAN ID.

    • Switch Specific Parameters—Select this check box to configure switch parameters for the VLAN profile.

    • Enable VLAN—Select this check box to enable VLAN.

    • Enable L3—(Optional) Select this check box to configure Layer 3 parameters.

  6. Click Create.

    Figure 6: VLAN Profile Configuration

  7. Assign the VLAN profile created to Access Switch, Aggregation Switch, Core Switch, and Mobility Gateway device functions and appropriate scope, as per the requirements.

  8. Repeat steps 3 to 6 for each VLAN.

For more information on the VLAN profile parameters, see VLAN Profile.

Configuring AP System Profile

You must configure country code, timezone, and other custom parameters for the AP using AP System profile.

Note:

If you created your sites with real street addresses or GPS coordinates, then the Timezone and Country Code parameters are automatically assigned based on the site's location that the AP belongs to. However, if you do not use real addresses for your sites, then follow these steps to configure the AP System Profile.

To configure an AP System profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select Library.

  3. On the System card, click AP System.

    Figure 7: AP System Profile Option

    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the AP System card, click Manage.

    The AP System list view is displayed.

  4. Click Create Profile.

  5. In the Create Profile side panel, configure the following AP System profile parameters:

    • Name—Enter the name of the AP system profile.

    • Country Code—Select the required country code from the drop-down list.

    • Timezone—Select the required timezone from the drop-down list.

  6. Click Create.

    Figure 8: AP System Profile Configuration

  7. Assign this AP System profile to Campus Access Point device function and appropriate scope, as per the requirements.

For more information on the AP System profile parameters, see AP System Profile.

Configuring AP Uplink Port Profile

You can configure AP Uplink Port profile to establish uplink connections for the APs.

Note:

This is an optional procedure as the APs use the default uplink configuration containing the following parameter values:

  • Select LAN Port(s)Ethernet 0/0

  • Native VLAN1

  • Allowed VLANsAll

  • Management VLANNative VLAN.

    However, if you want to customize these settings, follow these steps.

To configure an AP Uplink profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select Library.

  3. On the Interfaces card, click AP Uplink.

    Figure 9: AP Uplink Profile Option


    Alternatively, you can complete the following steps:

    1. On the Interfaces card, click Manage.

    2. On the AP Uplink card, click Manage.

    The AP Uplink list view is displayed.

  4. Click Create profile.

  5. In the Create AP Uplink Profile page, configure the following AP uplink profile parameters:

    • Name—Enter the name of the AP uplink profile.

    • Select LAN Port(s)—Select the required Ethernet port to be used for uplink from the drop-down list.

    • Port Mode—Select the Trunk radio button.

    • Native VLAN—Enter the VLAN ID to be used for Native VLAN.

    • Allowed VLANs—Enter specific VLANs, VLANs range, or All (default).

  6. Click Create.

    Figure 10: AP Uplink Profile Configuration

For more information on the AP uplink profile parameters, see AP Uplink Profile.

Step 2—Configuring Mobility Gateways

The following image displays the steps to configure Mobility Gateways on the network.

Figure 11: Mobility Gateway Configuration Steps

To configure the Mobility Gateways and get the clients connected over wireless network, complete the following steps:

  1. Setting the User Administrator Password for Mobility Gateways

  2. Configuring Management VLAN Profile

  3. Configuring Static Routing and Network Services

  4. Configuring AP Uplink Port Profile

Note:

Ensure that the Mobility Gateway is already provisioned using Zero Touch Provisioning (ZTP).

Setting the User Administrator Password for Mobility Gateways

The administrator user is configured for device management using SSH or console. You must create the user administrator profile for Mobility Gateways to set your own password.

To configure the user administrator password for Mobility Gateways, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select Global.

  3. Under Profiles Management page on the right, select Campus Access Point from the Device Function drop-down list.

  4. On the System card, click User Administration.

    Figure 12: Mobility Gateway User Administrator Profile Option

    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the User Administration card, click Manage.

    The User Administration list view is displayed.

  5. Click Create Profile.

  6. In the Create Profile side panel, configure the following parameters:

    • Create as a local profile—Select this option if you want to configure this profile as local.

      Note:

      The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.

    • Name—Enter the name of the user administration profile.

    • Password/Retype Password—Enter a password for the user administration profile.

    • Role—Select Admin from the drop-down list.

  7. Click Create.

    Figure 13: Mobility Gateway User Administration Profile Configuration

    The password is assigned to the user administrator.

    For more information, see User Administration Profile.

Configuring Management VLAN Profile

The Management VLAN Profile configuration defines the VLAN and associated Layer 3 parameters used for administrative access to Mobility Gateways, ensuring secure and segmented network management.

To configure management VLAN profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select Library.

  3. On the VLANs & Networks card, click VLAN.

    Figure 14: VLAN Profile Option


    Alternatively, you can complete the following steps:

    1. On the VLANs & Networks card, click Manage.

    2. On the VLAN card, click Manage.

    The VLAN list view is displayed.

  4. Click anywhere on the row of the management VLAN profile in the list view.

    The Edit Profile side panel is displayed.

  5. Under Advanced, ensure that the Enable L3 check box is selected.

    This configuration is referenced in the gateway system profile's IP settings.

  6. Ensure that the Admin State check box is selected.

  7. Click Update.

    Figure 15: Management VLAN Profile Configuration

  8. Assign the VLAN profile created to Mobility Gateway device function and appropriate scope, as per the requirements.

For more information on the VLAN profile parameters, see VLAN Profile.

Configuring Static Routing and Network Services

The configuration of static routing and essential network services such as DNS, NTP, and gateway profiles ensures reliable connectivity and service resolution across Mobility Gateways. This section includes the following steps:

Configuring Static Routing

You must configure Static Routing profiles to define the next hop or default gateway, enabling controlled and predictable traffic flow within the network.

To configure a Static Routing profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select Library.

  3. On the Routing & Overlays card, click Static Routing.

    Figure 16: Static Routing Profile Option


    Alternatively, you can complete the following steps:

    1. On the Routing & Overlays card, click Manage.

    2. On the Static Routing card, click Manage.

    The Static Routing list view is displayed.

  4. Click Create Profile.

  5. In the Create Profile side panel, configure the following parameters:

    • Name—Enter the name of the Static Routing profile.

    • IP Routes—Click the icon to add a default gateway for switches.

      1. In the Create IP Routes side panel, configure the following parameters:

        • Destination—Enter 0.0.0.0/0 as the destination IPv4 address.

        • Forwarding Type—Select Next Hop radio button.

        • Next Hop—Enter the next hop IPv4 address of the default gateway.

        • Next Hop—Enter the next hop IPv4 or IPv6 address in the text box.

      2. Click Create.

        Figure 17: IP Route Configuration

    • Device Specific Parameters—Select the Gateway/AOS-S Parameters check box.

    • In the Default Gateways table, click the icon to access the Create Default Gateways side panel.

      1. In the Default Gateways IP Address, enter the destination IPv4 address of the default gateway.

      2. Click Create.

  6. In the Create Profile side panel, click Create.

  7. Assign the static routing profile created to Mobility Gateway device function and appropriate scope, as per the requirements.

    Figure 18: Static Routing Profile Configuration

For more information on the static routing profile parameters, see Static Routing Profile.

Configuring DNS Server

The DNS server profile configuration enables Mobility Gateways to resolve domain names efficiently by specifying primary and secondary DNS servers for network services.

To configure a DNS Server profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select Library.

  3. On the System card, click DNS Server.

    Figure 19: DNS Server Profile Option


    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the DNS Server card, click Manage.

    The DNS Server list view is displayed.

  4. Click Create Profile.

  5. In the Create Profile side panel, configure the following parameters:

    • Name—Enter the name of the DNS Server profile.

    • DNS Servers—Click the icon to add a DNS server.

      1. In the Add DNS Server side panel, configure the following parameters:

        • IP Address —Enter the IP address for DNS server.

        • Device-Specific Parameters—(Optional) Select the Gateway check box.

        • Gateway Parameters—(Optional) Select the uplink VLAN from the Uplink VLAN drop-down list.

      2. Click Add.

    Figure 20: DNS Server Addition

  6. In the Create Profile side panel, click Create.

  7. Assign the DNS server profile created to Mobility Gateway device function and appropriate scope, as per the requirements.

Figure 21: DNS Server Profile Configuration

For more information on the DNS server profile parameters, seeDNS Server Profile.

Configuring NTP Server

NTP server configuration keeps Mobility Gateways synchronized with accurate system time, supporting consistent logging and network operations.

To configure an NTP Server profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select Library.

  3. On the System card, click NTP Server.

    Figure 22: NTP Server Profile Option


    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the NTP Server card, click Manage.

    The NTP Server list view is displayed.

  4. Click Create Profile.

  5. In the Create Profile side panel, configure the following parameters:

    • Name—Enter the name of the NTP server profile.

    • NTP Server—Click the icon to add an NTP server.

      1. In the Add NTP Server side panel, configure the following parameters:

        • Server Address—Select IPv4, IPv6, or FQDN.

          • IPv4—If you select IPv4, then enter the IPv4 address.

          • IPv6—If you select IPv6, then enter the IPv6 address.

          • FQDN—If you select FQDN, then enter the domain name.

        • iBurst Mode—(Optional) Select the check box to further hasten the synchronization.

      2. Click Add.

        Figure 23: NTP Server Addition

  6. In the Create Profile side panel, click Create.

  7. Assign the NTP server profile created to Mobility Gateway device function and appropriate scope, as per the requirements.

Figure 24: NTP Server Profile Configuration

For more information on the NTP server profile parameters, see NTP Server Profile.

Configuring Gateway System Profile

The Gateway system profile configuration sets system-level parameters such as time zone and IP settings, ensuring proper localization and network identification of Mobility Gateways.

To configure a Gateway System profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select Library.

  3. On the System card, click Gateway System.

    Figure 25: Gateway System Profile Option


    Alternatively, you can complete the following steps:

    1. On the System card, click Manage.

    2. On the Gateway System card, click Manage.

    The Gateway System list view is displayed.

  4. Click Create Profile.

  5. In the Create Profile side panel, configure the following parameters:

    • Name—Enter the name of the gateway system profile.

    • Device Timezone—Select a device time zone from the drop-down list.

    • System IP—Select the management VLAN interface as system IP address for the gateway.

    • Security—FirewallJumbo Frames Processing—(Optional) Select this check box that allows the gateway to process Ethernet frames larger than 1500 bytes.

  6. Click Create.

  7. Assign the gateway server profile to Mobility Gateway device function and appropriate scope, as per the requirements.

Figure 26: Gateway System Profile Configuration

For more information on the gateway system profile parameters, see Gateway System Profile.

Configuring Gateway Interface

To configure gateway interface, complete the following steps:

  1. Assigning IP Address to Management VLAN

  2. Configuring Gateway Interface Profile

Assigning IP Address to Management VLAN

At the device level, you must assign an IP address and prefix to the management VLAN profile, allowing the gateway to communicate on the network.

To assign IP address to the management VLAN, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.

    The Profiles tab is displayed.

  2. In the left navigation menu, select Devices.

    The Devices list view is displayed.

  3. Select a gateway from the list.

    The Profiles Management view for the selected gateway is displayed.

  4. Click the configuration icon.

  5. In the left navigation pane, click Devices.

  6. Click a Mobility Gateway from the Devices page list to access the device scope.

  7. On the VLANs & Networks card, click VLAN.

    Figure 27: Gateway VLAN Option

    Alternatively, you can complete the following steps:

    1. On the VLANs & Networks card, click Manage.

    2. On the VLAN card, click Manage.

    The VLAN list view is displayed.

  8. Click anywhere on the row of the management VLAN profile in the list view.

    The Edit Profile side panel is displayed.

  9. Select the Save as a local profile check box.

  10. Under Advanced, ensure that the Enable L3 check box is selected.

  11. Enter the IPv4 address and prefix in the IPv4 Address/Prefix parameter.

  12. (Optional) Enter the maximum transmission unit in MTU if you enabled Jumbo Frames Processing in Configuring Gateway System Profile

  13. Click Update.

    Figure 28: Management VLAN Profile Configuration

For more information, see VLAN Profile.

Configuring Gateway Interface Profile

The Gateway Interface Configuration Profile allows you to view gateway ports, configure Link Aggregation Groups (LAGs), and manage port settings to optimize bandwidth and reliability.

To configure Gateway Interface Configuration profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configurationicon.

    The Profiles tab is displayed.

  2. In the left navigation menu, select Devices.

    The Devices list view is displayed.

  3. Select a gateway from the list.

    The Profiles Management view for the selected gateway is displayed.

  4. On the Interfaces card, click Gateway Interface Configuration.

    Figure 29: Gateway Interface Configuration Option

    Alternatively, you can complete the following steps:

    1. On the Interfaces card, click Manage.

    2. On the Gateway Interface Configuration card, click Manage.

    The Gateway Interface Configuration list view is displayed. Additionally, the Gateway Interface Configuration page displays the faceplate representation of the selected gateway.

  5. Click the check box for the appropriate interface in the Port column or click anywhere on the row of the port you want to modify.

  6. In the Configure Interface side panel, configure the following parameters:

    • Network Parameters:

      • VLAN Mode—Select Trunk.

      • Native VLAN—Select the management VLAN from the drop-down list.

      • Allowed VLANs—Enter the allowed VLAN range.

    • VLAN Security(Optional):

      • Jumbo MTU—Select this check box if you use Jumbo frames.

      • LLDP Config—Select this check box.

      • LLDP Transmission—Select this check box.

      • LLDP Receive—Select this check box.

      • LLDP-MED—Select this check box.

  7. Click Save.

Figure 30: Edit Gateway Interface Configuration

For more information, see Gateway Interface Configuration Profile.

Assigning Gateway to a Cluster

Assigning a Mobility Gateway to a cluster enables high availability by grouping gateways under a shared configuration, ensuring seamless failover and consistent network performance.

To configure a gateway cluster profile, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configuration icon.

    The Profiles tab is displayed by default.

  2. In the left navigation menu, select Device Groups.

    The Device Groups table is displayed containing the list of device groups.

    Note:

    The profiles at the Device Group level are assigned a device group scope by default.

  3. Select a device group from which you want to create a gateway cluster profile.

    The Profiles Management page under Profiles tab is displayed.

  4. From the Device Function drop-down list, select Mobility Gateway as the device type.

  5. On the High Availability card, click Gateway Clustering Profile.

    Figure 31: Gateway Cluster Profile Option

    Alternatively, you can complete the following steps:

    1. On the High Availability card, click Manage.

    2. On the Gateway Clustering card, click Manage.

    The Gateway Clustering configuration page is displayed.

  6. Click Create Profile.

  7. In the Create Profile side panel, configure the following parameters:

    • Name—Enter the name of the gateway cluster profile.

    • Gateway Clustering—To add a gateway to the cluster, complete the following steps:

      1. Click + to open the Add Gateway side panel.

      2. Select a gateway from the Gateway drop-down list.

      3. Click Add.

  8. Click Create.

Figure 32: Gateway Cluster Profile Configuration

For more information, see Gateway Clustering Profile.

Step 3—Managing User Roles and Policies

Managing user roles and policies helps define access levels and enforce security controls, ensuring users connect with appropriate permissions while protecting network resources.

To configure roles and policies for Mobility Gateways, complete the following steps:

  1. Creating User Roles

  2. Creating Role-Based Security Policies

Creating User Roles

To create a user role, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configuration icon.

    The Configuration Overview page is displayed.

  2. Click Library in the left navigation pane.

  3. Click the Roles & Policies tab on the right.

  4. Under Roles card, click Manage.

    Figure 33: User Role Option

  5. Click Create Role.

    The Create Role side panel is displayed.

  6. Enter a name of the role in the Name parameter.

  7. Click Create.

    Figure 34: User Role Creation

  8. Assign the user role to Mobility Gateway and Campus Access Point device functions and the appropriate scope, as per the requirements.

  9. Repeat steps 5-8 to add more user roles.

Creating Role-Based Security Policies

To create a security policy and assign it to the user role, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configuration icon.

    The Configuration Overview page is displayed.

  2. Click Library in the left navigation pane.

  3. Click the Roles & Policies tab on the right.

  4. Under Security Policies card, click Manage.

  5. Under Role-based Policies card, click Manage.

    Figure 35: Security Policies Option

    Figure 36: Role-Based Policies Option

  6. In the Role-based Policies table, click Create Policy.

  7. In the Create Policy side panel, enter a policy name in the Name parameter.

  8. Click Create.

    Figure 37: Role-Based Policy Creation

    The policy is listed in the Role-Based Policies table.

    Note:

    From the Role-Based Policies table, you can define rules and restrictions for the newly-created role-based policy for secure network usage.

  9. In the Role-based Policies table, click the ellipsis icon for the policy you created and click Add Rule.

  10. In the Create Rule side panel, configure the following parameters:

    • Source—Select Access Role from the drop-down list.

    • Access Role—Select an access role from the drop-down list. You can also create a new access role by clicking the New Role option under Access Role. For more information, see Creating a Role.

    • Destination—Select Any from the drop-down list.

    • Service/Application—Select Any from the drop-down list.

    • Action—Select Allow from the drop-down list.

  11. Click Create.

  12. To assign the policy to the required device functions and appropriate scope, complete the following steps:

    1. In the Role-based Policies table, click the ellipsis icon for the policy you created and click Assign to open the Assign Profile panel.

    1. Under Device Function, select the Mobility Gateway and Campus Access Point check boxes.

      Figure 38: Device Function Assignment

    2. Click the + icon next to Scopes to open the Add Scope panel.

    3. Select Global from the Scope Level drop-down list.

    4. Click Add.

    5. In the Assign Profile panel, click Assign.

Step 4—Configuring the Wireless Network

To create and assign a WLAN profile to the AP, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the configuration icon.
    The Profiles tab is displayed.

  2. In the left navigation menu, select Library.

  3. On the Wireless card, click WLAN.

    Figure 39: WLAN Profile Option


    Alternatively, you can complete the following steps:

    1. On the Wireless card, click Manage.

    2. On the WLAN card, click Manage.

    The WLAN list view is displayed.

  4. Click Create profile.

  5. In the Create Profile page, configure the following WLAN profile parameters:

    • Name—Enter the name of the WLAN profile.

    • ESSID Name—Enter an ESSID name. This name defaults to the profile name.

    • 2.4 GHz/5 GHz/6 GHz—(Optional) Select one or all the radio bands that allow you to modify frequencies over which this ESSID will be broadcast.

    • Network Configuration—(Optional) Select one of the following options based on the requirement:

      • Most Compatible

      • Balanced

      • High Density

      • Custom

    • Traffic Forwarding Mode—Select the Tunnel radio button.

      Note:

      You must select Tunnel for AP and Mobility Gateway deployments. The Bridge option is for AP-only deployments. The Mixed option is for AP and Mobility Gateway, but allows some VLAN to be trunked to the switching fabric based on user session VLAN assignment. However, other user sessions are tunneled to the Mobility Gateway cluster.

    • Primary Gateway Cluster—Select the gateway cluster that client traffic will be tunneled to when connecting to this ESSID.

    • Default VLAN—Enter the default VLAN value of the WLAN profile. The default VLAN clients are used in the absence of any dynamic VLAN assignment.

      Alternatively, you can use a named VLAN by selecting the Use Named VLAN check box and selecting the named VLAN from the drop-down list.

    • Security Level—Select one of the following security levels from the drop-down list:

      • Enterprise

      • Personal

      • Open

    • Key Management—Select the appropriate security level for this ESSID from the drop-down list, depending on the security level selected.

    • Passphrase Format—Select one of the following passphrase formats from the drop-down list:

      • 64 hexadecimal chars

      • 8-63 chars

      Note:

      This parameter is available only when you select Personal as the Security Level, followed by WPA2-Personal, WPA Personal, Both (WPA2 and WPA), or WPA3 Personal option from the Key Management drop-down list.

    • Passphrase/Retype Passphrase—Enter a passphrase if you selected Personal as the Security Level.

    • Default Role - [Profile Name]—Select the Override default role check box, and a previously created role from the Default Role drop-down list.

      Note:

      If you created user roles and role-based policies, you can select one of them from the Default Role drop-down list. This is assigned to all clients that do not have a dynamic role assignment. For information about roles and role-based policies, see Manage Roles and Policies.

  6. Click Finish.

    Figure 40: WLAN Profile Configuration

  7. Assign the WLAN profile to the Campus Access Point device function and to the appropriate device group.

    Note:

    The device group contains the APs intended to connect to this cluster for the specified ESSID. However, it is not mandatory for the APs to be in the same device group as the cluster; they may belong to a different group.

The clients configured with the appropriate security method (such as PSK) for the ESSID are able to connect to the network, and their traffic is securely tunneled from the AP to the Mobility Gateways within the cluster.

For more information, see WLAN Profile.