Instant On Deployment Concepts

HPE Networking Instant On supports the following deployment combinations:

  • Access Point only
  • Switch only
  • Gateway only
  • Access Point and Switch
  • Access Point and Gateway
  • Switch and Gateway
  • Access Point, Switch, and Gateway

Access Point Only Deployment

You begin to create your site by powering on your Instant On APs and ensuring they are connected to the internet. A choice is presented to configure the APs in a private network or a router-based setup. The network you create when you go through the initial setup will be the default network in your site and cannot be deleted. The SSID of this default network will be in the read-write mode and can be modified as deemed necessary. However, the management VLAN assigned to this default network will be read-only and cannot be modified. Once you have completed the initial setup, you can choose to extend your network using a gateway, additional APs, or switches. In this deployment, you are allowed to create a maximum of 8 wireless networks on a site.

For more information, see Setting Up Your Wireless Network.

Switch Only Deployment

The initial setup using the Instant On mobile app or web application takes you through a step-by-step process of onboarding your switch. The switch must be powered on and connected to the internet to complete the onboarding process. A wired network is created on completing the initial setup and will serve as the default network for the site and cannot be deleted. Unlike the wireless networks, the wired network will not require you to create an SSID and password for the network. The site name is retained as the wired network name and a default management VLAN ID is set during this process. At a later point in time, you can choose to add Instant On APs or a gateway to the site by extending your network and following the process of creating a wireless SSID. In this deployment, you are allowed to create a maximum of 22 wired networks on a site.

For more information, see Setting Up Your Wired Network.

If there are any Instant On APs powered on and ready in the network, they will be discovered during the initial setup and added to the network along with the switch.

Access Point and Switch Deployment

This deployment is suitable for users whose network infrastructure includes a combination of wired Instant On switches and wireless Instant On APs. The initial setup is similar to that of the wireless network, where you are presented with two choices, to either connect your APs in a private network or a router-based setup. In this deployment, you are allowed to create a maximum of 30 networks (22 wired and 8 wireless) on a site. There are 2 types of scenarios involved when deploying AP and switch together in a site:

  • Deploying an AP and a Switch in Private Network Mode
  • Deploying an AP and a Switch in Router Mode

For more information, see AP Operating Modes section to Onboard your devices based on the preferred mode.

Gateway Deployment - with AP Switch or Both Devices

Use this deployment when the Instant On gateway is intended to serve as the primary routing device for the site. The Instant On gateway provides advanced security capabilities such as firewalling, and intrusion detection or prevention (IDS/IPS).

In this deployment, the Instant On gateway offers DHCP, DNS, traffic routing between LAN to WAN interface or WAN to LAN interface and firewall services for your network.

To ensure proper discovery and onboarding, the Instant On Gateway must be directly connected to the internet modem with no other device in between as follows:

  • Connect the primary WAN port of the Instant On gateway to the ISP-provided modem or to a device that provides internet access.
    • Port 4 on SG1004 gateway
    • Port 5 on SG2505P gateway
  • Connect Aruba Instant On APs or Switches to the LAN ports of gateway. This can be done during the initial setup or later by extending your network.

Once connected, the gateway will be discovered and onboarded using Instant On Web application or mobile app. Once the gateway is onboarded, it will provide the DHCP and DNS services, and all traffic will be routed from LAN to the WAN interface.

Once the onboarding is complete, connected devices such as switches and access points are automatically discovered through the LAN ports.

You can also use the secondary WAN port to connect to the secondary internet connection. The following are the secondary WAN ports that can be used for the secondary internet connection:

  • Port 3 on SG1004 gateway
  • Port 4 or Port 3 on SG2505P gateway. Port 4 is a 2.5G Ethernet port and Port 3 is a 1G Ethernet port.

The secondary connection provides backup and failover capabilities in the event when the primary connection is not available.

Direct and Indirect Connection

The Instant On gateway can be connected to the internet either directly or indirectly through an ISP-provided router-modem:

Direct Connection

The Instant On secure gateway connects directly to the internet using an Ethernet cable without any intermediate device.

Indirect Connection

The secure gateway connects to the internet through an intermediate device, such as an ISP-provided router-modem. In an indirect connectivity topology, it is important that the ISP-provided device allows the Instant On gateway to access the internet.

The following additional configurations may be required if the firewall function is active on both systems:

  • Client access should be disabled on at least one system. The recommended approach is to disable client access on the ISP-provided device and manage all access using the client access policy on the Instant On Secure gateway.
  • By default, remote access is blocked on the Instant On secure gateway. If remote access is required, it must be enabled on both the ISP-provided device and the Instant On secure gateway to allow traffic to pass through both layers.
  • If your setup involves two ISP connections and both are indirectly connecting the Instant On secure gateway to the internet, it is recommended to manage all firewall rules on the Instant on gateway.

For more information, see Setting Up Your Instant On Secure Gateway .