Controllerless Networks

Reply
Contributor I

IAP + ClearPass and dynamic VLAN

Hi, 

 

I am trying to figure out dynamic VLAN assigning with IAP and Clearpass.

In Clearpass I can create a Serivce that enforces different VLANs based on the authentication and user, but then in IAP when I choose VLAN assignment Dynamic I have to make a rule based on some attribute from Clearpass and choose what VLAN that user goes in to.

So then I have configured the VLAN on two places. This doesn't seem right. Is it possible to only configure the VLAN assignment in Clearpass?

 

I guess the option is to have Clearpass enforce a role to the user and in IAP make a VLAN rule that say "if role = X, send to VLAN Y". But I rather do all that kind of config in Clearpass.

 

Regards

Philip

 


Wireless network engineer consultant| @phivil | ACMP ACCP ACDX #759
Guru Elite

Re: IAP + ClearPass and dynamic VLAN

You would typically return the Aruba-User-Vlan radius attribute in your enforcement profile on ClearPass to set the VLAN for that user.


*Answers and views expressed by me on this forum are my own and not necessarily the position of Aruba Networks or Hewlett Packard Enterprise.*
ArubaOS 8.3 User Guide
InstantOS 8.3 User Guide
Airheads Knowledgebase
Contributor I

Re: IAP + ClearPass and dynamic VLAN

So then in IAP I will config: if Aruba-User-Vlan = 10, then assign VLAN 10?


Wireless network engineer consultant| @phivil | ACMP ACCP ACDX #759
Guru Elite

Re: IAP + ClearPass and dynamic VLAN

You do not need any rule configuration on the Instant side. The RADIUS VSA tells the IAP what to do.

Tim Cappalli | Aruba Security
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Contributor I

Re: IAP + ClearPass and dynamic VLAN

Oh. Then I can only have a default vlan and no other rules?


Wireless network engineer consultant| @phivil | ACMP ACCP ACDX #759
Guru Elite

Re: IAP + ClearPass and dynamic VLAN

If you’re returning VLANs via a RADIUS response, then you don’t need rules on the IAP.

Tim Cappalli | Aruba Security
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Contributor I

Re: IAP + ClearPass and dynamic VLAN

That's what I wanted to hear! (read)

Thank you verry much.


Wireless network engineer consultant| @phivil | ACMP ACCP ACDX #759
Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: