Aruba Instant On Help Center
You are here: Mobile Help > Configuring Networks > Employee Network

Employee Network

An Employee network is a classic Wi-Fi network. This network type is used by the employees in an organization and it supports passphrase-based (PSK) or 802.1X-based authentication methods. Employees may access the protected data through the employee network after successful authentication. The employee network is selected by default during a network profile configuration.

 

The very first employee network you create for the site cannot be deleted unless you choose to delete the site entirely from your account.

To configure an employee network:

1. Tap Networks tile on the Instant On mobile app home page.

2. Tap Add () and select the Wireless tab as the Network type. This tab appears only when your site has both wired and wireless networks.

3. Select Employee, under Usage to indicate that the network is for an enterprise.

4. Enter a Network name for the employee network. This will also be broadcasted as the SSID for the WLAN network.

5. Choose a Security level for the network and update the required fields.

Network password (PSK)—Secures the network using a shared password (PSK). To set the network with password, click the Password tab under Security and create a password of your choice in the Network password field. The following options can be configured.

WPA2 Personal

WPA2+WPA3 Personal

If you want to use a RADIUS authentication server, tap the RADIUS tab.

 

You must configure the RADIUS server to allow APs individually or set a rule to allow the entire subnet.

Authentication server (RADIUS)—Secures the network using a higher encryption RADIUS authentication server. Update the following fields:

WPA2 Enterprise

WPA2 + WPA3 Enterprise

Server IP address—Enter the IP address of the RADIUS server.

Shared secret—Enter a shared key for communicating with the external RADIUS server.

6. To configure the other radius parameters, tap More Radius parameters. The Authentication Servers screen is displayed.

7. Configure the following parameters for the Primary RADIUS Server.

Server timeout—Specify a timeout value in seconds. The value determines the timeout for a RADIUS request. The Instant On AP attempts to send the request several times (as configured in the Retry count) before the user gets disconnected. For example, if the Timeout is 5 seconds, Retry counter is 3, user is disconnected after 20 seconds. The default value is 5 seconds.

Retry count—Specify a number between 1 and 5. Retry count indicates the maximum number of authentication requests that are sent to the server group, and the default value is 3 requests.

Authentication port—Enter the authentication port number of the external RADIUS server within the range of 1–65535. The default port number is 1812.

Network Access Attributes - Configure the following settings under Network Access Attributes, if you wish to proxy all RADIUS requests from the Instant On AP to the client.

NAS identifier—Enter a string value for RADIUS attribute 32, NAS Identifier, to be sent with RADIUS requests to the RADIUS server.

NAS IP address—Select one of the following options if your Instant On devices are configured in a private network mode. The options below determine how the RADIUS authentication takes place across all networks.

 

NOTE: This option is grayed out if the Instant On AP is configured as a primary Wi-Fi router on the network. In which case each AP in the network will send RADIUS requests to the server with a matching Source IP address and NAS IP address.

Use device IP (default)—This is the default setting. The RADIUS requests and NAS IP address will originate from each device authenticating the clients.

Use a single IP—The RADIUS and NAS IP address will originate from a single IP address representing the site. Enter the NAS IP address for the site.

8. To configure a Secondary RADIUS Server, slide the toggle switch to the right () and update the required fields.

9. To Send RADIUS Accounting requests, slide the toggle switch to the right () and update the Accounting Port field.

10. Click Save.

 

After you configure an Employee network and save its settings for the first time, a toggle switch appears in the Employee Details page indicating the network is currently Active (). Use this switch to enable or disable the employee network.

 

This option is grayed out if the Instant On AP is configured as a primary Wi-Fi router on the network. In which case each AP in the network will send RADIUS requests to the server with a matching Source IP address and NAS IP address.

Use device IP (default)—This is the default setting. The RADIUS requests and NAS IP address will originate from each device authenticating the clients.

Use a single IP—The RADIUS and NAS IP address will originate from a single IP address representing the site. Enter the NAS IP address for the site.

11. To configure a Secondary RADIUS Server, slide the toggle switch to the right () and update the required fields.

12. To Send RADIUS Accounting requests, slide the toggle switch to the right () and enter the —Enter the accounting port number within the range of 1–65,535 in the Accounting port. This port is used for sending accounting records to the RADIUS server. The default port number is 1813.

13. Tap the back arrow () to return to the employee network details page.

 

After you configure an Employee network and save its settings for the first time, a toggle switch appears in the Employee Details page indicating the network is currently Active (). Use this switch to enable or disable the employee network.

Modifying the Employee Network Name and Password

To modify the network name or password of the employee network in the Aruba Instant On mobile app, follow these steps:

1. Tap Networks on the Instant On home screen. The Networks screen is displayed.

2. Select the employee network from the Networks list to view the Employee Network Details screen.

3. Under Identification, enter a new name under Network name to change the main network name or a new password under Network password to change the main network password. A warning message appears, indicating that changes to the network settings will disconnect all clients currently accessing the network.

4. Tap DONE to save the settings.

More Options

The More options drop-down in the Aruba Instant On mobile app allows you to configure following settings for clients on employee networks:

IP and Network Assignment

Schedule

Bandwidth Usage

Network Access

Wireless Options

Shared Services

Viewing Client Count

/*]]>*/