Aruba - Passpoint Configuration
Configure Passpoint (Hotspot 2.0) on Aruba IAP, Mobility Controllers, or Aruba Central to enable automatic WiFi authentication through IronWifi's cloud RADIUS service. This provides seamless WPA2/WPA3-Enterprise connections without manual network selection or splash pages.
Supported Platforms
| Platform | Notes |
|---|---|
| Aruba IAP (Instant Access Points) | Standalone/cluster mode |
| Aruba Mobility Controllers | Centralized deployment |
| Aruba Central | Cloud-managed |
Prerequisites
In Aruba:
- Aruba access points with Hotspot 2.0 support
- ArubaOS 8.x or Instant 8.x or later
- Administrator access
In IronWifi Console (complete these first):
- Create a Network and note the RADIUS details
- Enable Passpoint on the network
- Configure realm, operator name, and domain settings
Aruba IAP Configuration
IAP Web Interface Configuration
Step 1: Configure RADIUS Server
- Log in to the IAP web interface
- Go to Security > Authentication Servers
- Click + to add new server:
- Name: IronWifi
- IP Address: IronWifi RADIUS IP
- Auth Port: 1812
- Accounting Port: 1813
- Shared Key: Your RADIUS secret
Step 2: Create Wireless Profile
- Go to Networks
- Click + to create new network
- Configure:
- Name: Passpoint-Network
- Primary Usage: Employee
- SSID: Your SSID name
Step 3: Configure VLAN and Security
- In VLAN tab, configure appropriate VLAN
- In Security tab:
- Security Level: Enterprise
- Authentication Server: IronWifi
Step 4: Enable Hotspot 2.0
- In network settings, find Hotspot 2.0 section
- Enable Hotspot 2.0
- Configure:
Network Information:
- Internet: Yes
- Access Network Type: Free Public Network
- Venue Group: Business
- Venue Type: Unspecified
Operator Information:
- Operator Friendly Name: Your organization
- Domain Name:
ironwifi.net
Roaming Consortium:
5A03BA0000
004096
NAI Realm:
- Realm:
ironwifi.com - EAP Method: EAP-TTLS
- Inner Auth: PAP, MSCHAPv2
- Save configuration
IAP CLI Configuration
# Configure RADIUS server
wlan auth-server IronWifi
ip 1.2.3.4
port 1812
acctport 1813
key your-secret
# Create WLAN profile
wlan ssid-profile Passpoint-Network
essid Passpoint
type employee
opmode wpa2-aes
auth-server IronWifi
# Configure Hotspot 2.0
hotspot hs20-profile Passpoint
internet
access-network-type free-public
venue business
domain-name ironwifi.net
operator-name eng "IronWifi"
roaming-consortium 5A03BA0000
roaming-consortium 004096
nai-realm ironwifi.com eap-ttls pap mschapv2
# Apply to SSID
wlan ssid-profile Passpoint-Network
hs20-profile Passpoint
Aruba Mobility Controller Configuration
Web Interface
Configure RADIUS Server
- Go to Configuration > Security > Authentication > Servers
- Add new RADIUS server:
- Name: IronWifi
- Host: IronWifi RADIUS IP
- Auth Port: 1812
- Acct Port: 1813
- Key: Your shared secret
Configure Server Group
- Go to Server Groups
- Create new group and add IronWifi server
Create Hotspot 2.0 Profile
- Go to Configuration > Wireless > AP Configuration
- Select Hotspot 2.0
- Add new profile:
General Settings:
- Profile Name: Passpoint-Profile
- Internet: Yes
- Network Type: Free public network
Venue:
- Group: Business
- Type: Unspecified
Domain:
- Domain Name:
ironwifi.net
Operator:
- Language: eng
- Name: Your Organization
Roaming Consortium:
- Add OIs:
5A03BA0000,004096
NAI Realm:
- Realm:
ironwifi.com - EAP Method: EAP-TTLS
Apply to SSID
- Go to WLANs
- Create or edit WLAN
- Assign Hotspot 2.0 profile
- Configure WPA2-Enterprise security
Controller CLI Configuration
# RADIUS Server
aaa authentication-server radius "IronWifi"
host 1.2.3.4
key your-secret
aaa server-group "IronWifi-Group"
auth-server IronWifi
# Hotspot 2.0 Profile
hotspot hs2-profile "Passpoint"
internet
access-network-type free
venue-group business
venue-type unspecified
domain-name ironwifi.net
operator-name eng "IronWifi"
roaming-oi 5A03BA0000
roaming-oi 004096
nai-realm ironwifi.com encoding utf8 eap-type eap-ttls inner-auth pap
# WLAN Configuration
wlan ssid-profile "Passpoint-SSID"
essid "Passpoint"
opmode wpa2-aes
hs2-profile "Passpoint"
wlan virtual-ap "Passpoint-VAP"
ssid-profile "Passpoint-SSID"
aaa-profile "IronWifi-AAA"
Aruba Central Configuration
Cloud Portal Setup
- Log in to Aruba Central
- Navigate to your group
- Go to WLANs
- Create new WLAN or edit existing
Hotspot 2.0 Configuration
- In WLAN settings, enable Hotspot 2.0
- Configure:
- Internet Access: Enabled
- Network Type: Free public
- Domain:
ironwifi.net - Operator Name: Your organization
- Add Roaming Consortium OIs
- Configure NAI Realm
- Save and push configuration
Troubleshooting
Network Not Discovered
- Verify Hotspot 2.0 is enabled
- Check GAS/ANQP responses
- Verify client Passpoint support
- Review AP logs
Authentication Issues
- Test RADIUS connectivity
- Verify shared secret
- Check IronWifi authentication logs
- Verify NAI realm configuration
Debug Commands (Controller)
# Show Hotspot 2.0 status
show hotspot hs2-profile
# Show ANQP statistics
show ap debug hotspot anqp
# Check client association
show user-table
# RADIUS debugging
debug aaa events all