Use this guide to configure Aruba controllers and Access Point Beacons (APBs) with AOS 8.2.x for use with Meridian Beacon Management and Asset Tracking.
When an Aruba Tag is heard by an access point (AP), the AP sends the Tag's RSSI value to the Meridian Editor. The Editor uses the highest weighted average RSSI value of the Aruba Tag heard by three APs to track its location on a map. Asset tracking is a continual process for all Aruba Tags being tracked for a location.
- Ensure correct Clock/NTP services
- Configure preferred DNS to reach *.meridianapps.com
Complete These Steps
Complete these steps to enable Meridian Asset Tracking.
- Turn on the embedded Bluetooth in your APs and configure your infrastructure for Beacons Management.
- Install the DigiCert root certificate on your Managed Devices (MDs) also known as your local controller(s)
- Configure the Web Secure Socket between your controller and the Meridian back-end servers. This should be done on your MDs/local controllers.
- Deploy your Aruba Access Point Beacons (APB) using the Beacons app.
- Configure and Deploy your Aruba Asset Tags using the Tags app.
Notes on Web Secure Socket for Asset Tracking
Information Needed for Meridian Editor Aruba Network Configuration
Before you begin, you'll need to gather or set the following information in order to properly configure your controller for asset tracking.
|Controller or IAP||Value|
Beacons Management URLs ---
|Global Beacons Management URL||https://edit.meridianapps.com/api/beacons/manage|
|EU Beacons Management URL||https://edit.eu-meridianapps.com/api/beacons/manage|
|Access Token||Access Token (available in Meridian Editor)|
|BLE Operation Mode||Beaconing|
|Global Tag Ingestion URL ---|
|BLE Asset Tag Ingestion endpointURL||wss://tags.meridianapps.com/streams/v1beta1/ingestion/tags/websocket|
|EU Tag Ingestion URL ---|
|EU BLE Asset Tag Ingestion Endpoint URL for **6.5.2.x/6.5.3.x**||wss://tags-eu.meridianapps.com/streams/v1beta1/ingestion/tags/websocket|
Aruba Controller-based WLAN Configuration
The Aruba Wi-Fi network infrastructure is configured using an Aruba controller and APs. Configure a controller with Meridian configuration values and it will propagate that configuration to all connected APs.
The controller should have DNS configured and able to reach
Generate an Access Token for Communicating to the Meridian Server.
To get started, create your access token in the Meridian Editor.
- In the sidebar menu click Beacons, then select, "Beacons Management" from the top navigation menu, and then click Generate a New Access Token to get started.
- You'll need to copy your Access token and use in a later step to configure your infrastructure.
Configuring Beacons Management
- In the controller web UI, go to the Configuration tab.
- In the sidebar navigation menu, click System.
- In the top navigation menu, select Profiles.
- Under All Profiles, select AP.
- In the AP System pane, indicate the system profile used by your APs.
- Open the Advanced setting pane.
- In the BLE Endpoint URL field, enter:
- In the BLE Auth Token field, enter the Beacons Management auth token value.
- In the BLE operation mode field, enter
Configuring for Asset Tracking
Adding DigiCert Root Certificate to the Aruba Controller
The websocket endpoint uses the
wss (secure websockets) protocol and the server certificate is validated by the websocket library. When using a Meridian endpoint (with the *.meridianapps.com domain), the server is signed by a DigiCert root certificate, that requires the user to add the root CA certificate to the controller.
Uploading the certificate to the controller can be done under the Configuration > Management > Certificates menu.
Select PEM as the certificate format and Trusted CA as the certificate type.
The root CA certificate for Meridian is available at:
Meridian Asset Tracking was previously using a GeoTrust Root Certificate for SSL signing. If you had previously installed this cert, you can safely delete it from the WebGUI, or from CLI using the following statements;
#show crypto-local pki TrustedCA (find the name of the GeoTrust Root Cert) #configure terminal #no crypto-local pki TrustedCA <GeoTrust cert name>
Configure the Web-Secure Socket (WSS) in the Aruba Controller CLI
At this time, Configuration of WSS is only available using the controller CLI.
This configuration should be done on the local controller
#configure terminal (config) #ble_relay mgmt-server type ws wss://tags.meridianapps.com/streams/v1beta1/ingestion/tags/websocket or for EU-hosted instances (config) #ble_relay mgmt-server type ws wss://tags-eu.meridianapps.com/streams/v1beta1/ingestion/tags/websocket