Aruba S2500 Mobility Access Switch

The Aruba Networks™ S2500 Mobility Access Switch is a new class of product that brings user role-based access to wired networks.

Like other Mobility Access Switches, the S2500 is an integral part of the Aruba Mobile Virtual Enterprise (MOVE) architecture, which delivers secure virtualized access services to users, independent of their location, access method, device or application.

The S2500 is available in four models with 24 or 48 10/100/1000BASE-T ports and four fixed Gigabit Ethernet/10 Gigabit Ethernet uplink ports. Power-over-Ethernet (PoE) is available with up to 30 watts per port based on the IEEE 802.3af PoE and 802.3at PoE+ standards.

This provides network connectivity for Ethernet devices such as virtual desktops, IP phones, videophones, classroom peripherals, medical devices, point-of-sale devices and security cameras as well as any 802.11n Wi-Fi access point (AP).

The S2500 Mobility Access Switch features a very compact form factor and quiet operation, which makes it ideal for deploying in branch offices and small offices.

Discuss Mobility Access Switches at Airheads Social

VoIP using Mobility Access Switches

Aruba S2500 Mobility Access Switch Data Sheet

Brandeis Addresses BYOD

ATB Financial Goes Wired and Wireless

Get a Quote


Physical Specifications

  • S2500-24T: 24×10/100/1000BASE-T RJ-45 + 4xSFP/SFP+
  • S2500-24P: 24×10/100/1000BASE-T PoE RJ-45 + 4xSFP/SFP+
  • S2500-48T: 48×10/100/1000BASE-T RJ-45 + 4xSFP/SFP+
  • S2500-48P: 48×10/100/1000BASE-T PoE RJ-45 + 4xSFP/SFP+

Common interface feature support (all models)

  • Diagnostic LEDs (link/admin/duplex/PoE/speed/fault)
  • Auto-negotiation and auto MDI/MDIX support
  • Time domain feflectometry (TDR)
  • PoE feature support (P models)
  • IEEE 802.3af: PoE (15.4 watts)
  • IEEE 802.3at: PoE+ (30 watts)
  • Aruba efficient PoE (priority, guard-band and time range)
  • LCD management display
  • RJ-45/mUSB console port (RS-232)
  • Out-of-band 10/100/1000BASE-T management port
  • USB interface for software/configuration files

Uplink Interfaces

Fixed 4x1000BASE-X/10GBASE-X SFP/SFP+ (SFP/SFP+ purchased separately)
Supported SFP/SFP+ transceivers

  • 10GBASE-LR 1310-nm SFP+ (LC) for up to 10 kilometers over SMF
  • 10GBASE-SR 850-nm SFP+ (LC) for up to 300 meters over MMF (OM3)
  • 10GBASE-LRM 1310-nm SFP+ (LC) for up to 220 meters over MMF (OM2)
  • 1000BASE-LX 1310-nm SFP (LC) up to 10 kilometers over SMF
  • 1000BASE-SX 850-nm SFP (LC) up to 550 meters over MMF (OM2)
  • 1000BASE-T SFP (RJ-45) up to 100 meters (CAT5)
  • Direct Attach Cable – Twinax (50 cm, 1 m, 3 m or 7 m lengths)


  • S2500-24P/24T: 128 Gbps/95 Mpps
  • S2500-48P/48T: 176 Gbps/131 Mpps

Power Options

  • Integrated power supply
  • Autosensing 100-240 VAC, 150 watts (T models)
  • Autosensing 100-240 VAC, 580 watts (P models)
  • PoE budget: 400 watts

Layer 2 Features and Scaling

MAC addresses per system:


Jumbo frames:

9,216 bytes

Number of VLANS:


Port-and MAC-based VLAN

IEEE 802.1AB: Link-layer discovery protocol (LLDP) Device discovery and advertisement
Voice VLAN support using LLDP-MED

Cisco dscovery protocol (CDP) Device discovery
Voice VLAN support

IEEE 802.1Q:

VLAN tagging

IEEE 802.1D:

Spanning tree protocol (STP)

IEEE 802.1w:

Rapid reconfiguration of spanning tree protocol (RSTP)

IEEE 802.1s:

Multiple instances of spanning tree protocol (MSTP)

Maximum number of supported instances:


Rapid per-VLAN spanning tree plus (PVST+)

Spanning tree protocol features

Root guard
Loop guard

Aruba loop protect

Link aggregation groups

IEEE 802.3ad: Link-aggregation control protocol (LACP)
Number of link aggregation groups: 64
Number of ports per aggregation group: 8

Aruba Hot Standby Link (HSL)

IEEE 802.3ah: Ethernet operations, administration and maintenance (OAM)

Layer 3 Features and Scaling
Unicast routes in hardware: 8,000
Routed VLAN interface (RVI)
Loopback interface
Static routing
Open shortest path first (OSPF) v2
DHCP server/client
DHCP relay (including Option 82)
Network time protocol (NTP)


Operating temperature:

0°C to 50°C

Storage Temperature:

-40°C to 70°C

Operating Humidity:

5% to 95% non-condensing

Operating Altitude:

10,000 feet

Acoustic Noise:

42 dB with AC power supply



1.75″ (44mm)


17.5″ (445mm)


12.0″ (305mm)



10.0lbs (4.54kg)


12.1lbs (5.5kg)


10.9lbs (4.96kg)


13.3lbs (6.2kg)


MAC authentication
RADIUS (device management, 802.1X, accounting)
TACACS+ (Device Management and accounting)
LDAP (802.1x)
Digital certificates
Internal user database
Aruba Tunnel-Node
Access control lists (ACLs)
Storm control
IPv6 router-advertisement (RA) guard
DHCP guard
MAC limiting

Multicast Features and Scaling

Multicast routes in hardware: 2,000
PIM sparse mode (PIM-SM)
IGMP v1/v2
IGMP snooping
Multicast listener discovery (MLD) v1

Quality of Service (QOS)

IP precedence
QoS trust (802.1p/DSCP/Auto)
QoS classification by ACL, user and interface
Policer classification by ACL, user and interface
Egress strict priority queuing/low-latency queuing (LLQ)
Eight hardware queues per port

Management and Monitoring

Command line interface (serial, telnet, SSHv2)
Graphical user interface (HTTP/HTTPs)
AirWave management platform
SNMP v1, v2c, v3
IPv6 management
Port mirroring (single destination)
Remote monitoring (RMON)

Warranty and Support

Limited lifetime warranty (all models) includes:
Return-to-factory hardware replacement with following business day shipment of failed product
24×7 access to Aruba’s Technical Assistance Center (TAC) for 90 days after the purchase date
Warranty coverage as long as the original purchaser owns the product
Power supply and fans are covered for five years from initial purchase
ArubaCare Support provides additional product support options directly through Aruba or via an authorized Aruba reseller. Click here for more details.

Safety Certifications

UL-UL60950-1 (second edition)
C-UL to CAN/CSA 22.2 No.60950-1 (second edition)
TUV/GS to EN 60950-1, Amendment A1-A4, A11
CB-IEC60950-1, all country deviations

Electromagnetic Compatibility Certifications

FCC 47CFR Part 15, Class A
EN 55022 Class A
ICES-003 Class A
VCCI Class A
CISPR 22 Class A
EN 55024

Environmental Certifications

Reduction of Hazardous Substances 5 (RoHS-5)

Aruba ClearPass QuickConnect

ClearPass QuickConnect offers an easy way for users to self-configure their Windows, Mac OS X, iOS, and Android to support 802.1X authentication on wired and wireless networks.

Automatic detection of the OS

Automatic configuration of network settings

Ready to go without helpdesk interaction

Device configuration is often the most difficult part of deploying 802.1X and strengthening network access security.

ClearPass QuickConnect changes this by dramatically streamlining and simplifying device configuration for IT and end users alike.

Creating a uniquely simplified workflow, ClearPass QuickConnect facilitates and accelerates bring-your-own-device (BYOD) initiatives, propagates the deployment of more secure network access using 802.1X, and reduces helpdesk calls and IT overhead.

Key features:

  • Cloud-hosted provisioning utility makes it easy to create 802.1X deployment packages for endpoint devices.
  • 802.1X deployment packages are easily installed on endpoint devices and automatically configured through a simple user-driven wizard.
  • Customizable user-driven device configuration wizard.
  • Enables endpoint posture and health-check settings.
  • Automatically downloads Aruba ClearPass OnGuard™ agents and other applications.

Supported operating systems and supplicants:

  • Windows XP, Vista and 7
  • Mac OS X
  • iOS – iPhone, iPad and iPod
  • Android
  • SecureW2 client

Aruba ClearPass OnGuard

Enterprise-class endpoint protection, advanced posture assessments and health checks

An application for the ClearPass Policy Manager platform, ClearPass OnGuard performs automated endpoint posture assessments on leading computer operating systems to ensure that compliance is met before devices connect to wireless and wired networks.

Running on the ClearPass Policy Manager platform, the advanced network access control (NAC) and network access protection (NAP) framework in ClearPass OnGuard delivers exceptional protection against vulnerabilities.

ClearPass OnGuard supports a wide range of operating systems and versions:

  • Microsoft – Support for Windows 7, Windows Vista, Windows XP, Windows 2000 and 2003.
  • Apple – Support for Mac OS X.
  • Linux – Support for Red Hat Enterprise Linux 4 and above, Community Enterprise Operating System (CentOS) 4 and above, Fedora Core 5 and above, and SUSE Linux 10.x.

In addition to endpoint posture and health checks on anti-virus, anti-spyware and personal firewall applications, OnGuard agents perform advanced health checks that specify how to handle the use of peer-to-peer applications, USB storage devices and bridged network interfaces.

When running persistent OnGuard agents on endpoints, ClearPass Policy Manager can centrally identify and manage health-check settings, send system-wide notifications and alerts, and allow or deny network access.

Key Features

  • Enhanced capabilities for endpoint compliance and control, including NAC and NAP.
  • Supports Microsoft, Apple, and Linux operating systems.
  • Anti-virus, anti-spyware, firewall checks and more.
  • Optional auto-remediation and quarantine capabilities.
  • Peer-to-peer application checks, process checks and registry-key checks with remediation.
  • System-wide endpoint messaging, notifications and session access control.
  • Centrally view the online status of all devices from the ClearPass Policy Manager platform.

Aruba ClearPass Guest

The industry’s most secure, scalable and customizable guest network access solution

An application for the ClearPass Policy Manager platform, ClearPass Guest is a scalable, easy-to-use visitor management solution that delivers secure wired and wireless network access to guests, employees, contractors and their mobile devices.

Greatly simplifying visitor management, ClearPass Guest streamlines workflow processes, allowing operators or sponsors – receptionists, even coordinators and other non-IT staff – to create temporary accounts for Wi-Fi access.

Guests can also self-register for network access. Once registered, ClearPass Guest delivers account login credentials to users via print, SMS text message or email. Accounts can be set to expire automatically after a specific number of hours or days.

Scalable to satisfy the needs of large enterprises and multisite networks, ClearPass Guest manages secure, role-based access for hundreds of thousands of concurrent users.

ClearPass also enhances the guest experience by enabling organizations to create a branded look and feel on visitor registration pages. Organizations can post news updates, discount offers, upcoming events and other customized content.

Key features:

  • A ClearPass Policy Manager starter-bundle includes ClearPass Guest.
  • Create and modify temporary user accounts; delete or set accounts to automatically expire.
  • Scales to support thousands of concurrent users with minimal IT involvement.
  • Unique username and password per user.
  • Guests and employees can register for access through a customizable web interface.
  • Deliver guest account credentials via print, SMS or email to simplify registration.
  • Customizable skin technology enables the creation of uniquely branded captive portal and guest login pages.

Aruba ClearPass Onboard

Automated mobile device provisioning and configuration for secure BYOD

An application for the ClearPass Policy Manager platform, ClearPass Onboard automatically provisions and configures personally-owned mobile devices – Windows, Mac OS X, iOS and Android 2.2 and above – enabling them to securely connect to the network.

ClearPass Onboard lets users securely and automatically provision and configure their own smartphones, tablets and laptops.

With ClearPass Onboard, it’s easy for employees, contractors and partners to self-configure their own mobile devices for BYOD. The ClearPass registration portal automatically detects a device’s operating system and presents the user with the appropriate configuration package.

ClearPass Onboard provides an incredibly simple way to configure wireless, wired and VPN settings, apply unique device credentials, and ensure that users securely connect their devices to 802.1X-enabled networks with minimal IT involvement.

The result is a streamlined workflow that allows IT helpdesk personnel to automate and secure multiple processes that are required to successfully carry out BYOD initiatives while improving the user experience.

ClearPass Onboard also significantly increases the amount of actionable information that is captured for troubleshooting, user- and device-based policies, and compliance and reporting requirements.

Key features:

  • Enables users to self-register and securely onboard multiple devices.
  • Supports Windows, Mac OS X, iOS and Android operating systems.
  • Automates the configuration of network settings for wired and wireless endpoints.
  • Unique provisioning and revocation of device-specific credentials.
  • Contains built-in public key infrastructure (PKI).
  • Uses profiling to identify device type, manufacturer and model.
  • Provides BYOD visibility and centralized policy management capabilities