They play a vital role in helping org's manage their remote office/Branch office / Home office frameworks. Aruba is a leader in this space.
They have wide variety of products that include Remote Access Points -RAP, IAP - Intelligent Access points , controllers , Clear Pass and Aruba Central - SD-wan. Here predominantly i will take you through some of the architecture's that i am familiar with.
Let's talk about the architecture of owning multiple retails stores/ different branches / franchise stores around different locations in a country/ different country.
In each branch, we need a 7024/7010 controller with code versions 6x or 8x.
Branch Gateway - 7010/7024 controller
Switches - 3010 Hp
IAP - 515 Model Aruba
Destination - Orchestrator
A7240XM - Model - Code version - 6x/8x
Aruba Central config
Groups config in Central.
Below Diagram for getting an overview.
Traffic Flow
Network devices are connected to the switch and switch is connected to controller 7010/7024.
Modem uplink will be provided to controller and using which the controller will communicate outside this LAN.
Access Points will be providing WLAN to the branch. The same will be connected wired to either the switch or controller.
Now for the first time when connected to the internet, the controller will try to reach out to -Aruba Activate (Aruba Activate is a cloud-based service that helps provision your Aruba devices and maintain your inventory. )
In Activate we will be having the groups created and each group will contain the gateway IP to which the controller has to contact. So it's basically a phone book but a secured one so that no other device apart from the devices owned by the organization can get into the conversation.