Users Guide

Table Of Contents
Group-Based Device Sharing
Dell Networking W-Series ArubaOS 6.4.x AirGroup supports sharing AirGroup devices such as AppleTV, Printer,
and so on to a User Group using CPPM. This is an add-on to the existing device sharing mechanisms such as
username, user-role, and location based device sharing. A User Group is a logical association of users.
A user can be a part of groups that are defined in Active Directory. User group attribute for each user in a
controller is learnt, when a user is associated to wireless network. In ArubaOS, this is initially learnt in auth
module (authentication process). Auth module sends RADIUS request to RADIUS server as a part of 802.1x
authentication and the RADIUS server fetches the user group attribute in the form of vendor specific attribute
(VSA) from the Active Directory. Subsequently, AirGroup obtains this information from Auth module. This is
similar to user’s role, however, a user can be a part of more than one groups.
When AirGroup learns about a new device, it interacts with ClearPass Guest to obtain the shared attributes.
Starting from Dell Networking W-Series ArubaOS 6.4.x, the shared group(s) attribute is also obtained along
with the following attributes:
l Device owner
l Shared location(s)
l Shared user(s)
l Shared role(s)
The group based device sharing feature is supported in CPPM 6.3 and higher versions.
A user can be a part of maximum 32 user groups. This needs to be defined as comma separated string in Active
directory. Each group name can contain a maximum of 63 characters and the entire group name strings cannot
exceed 320 characters.
The AirGroup policy engine is enhanced to compare the user’s group membership (obtained using auth
module) and shared groups to determine if a user can discover the specific AirGroup server or not.
Sample Configuration
The following example displays the status of the AirGroup server (Apple TV, AirPrint Printer, Google
ChromeCast, and so on) in a controller:
(host) #show airgroup servers
AirGroup Servers
----------------
MAC IP Type Host Name Service VLAN Wired/Wireless
--- -- ---- --------- ------- ---- --------------
5c:3c:27:14:6e:01 10.15.121.240 mDNS airplay 2 wireless
Role Group Username AP-Name
---- ----- -------- -------
authenticated Mathematics Mike 104_AP105
Num Servers: 1, Max Servers: 2000.
The following example displays the shared group information for devices registered in ClearPass Guest:
(host) #show airgroup cppm entries
ClearPass Guest Device Registration Information
-----------------------------------------------
Device device-owner shared location-id AP-name shared location-id AP-FQLN
------ ------------ -------------------------- --------------------------
00:1e:65:2d:ae:44 N/A
shared location-id AP-group shared user-list shared group-list shared role-list
Dell Networking W-Series ArubaOS 6.4.x | User Guide AirGroup |
1063