Controllerless Networks

last person joined: 3 days ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

IAP + ClearPass and dynamic VLAN

This thread has been viewed 4 times
  • 1.  IAP + ClearPass and dynamic VLAN

    Posted Mar 30, 2017 02:51 PM

    Hi, 

     

    I am trying to figure out dynamic VLAN assigning with IAP and Clearpass.

    In Clearpass I can create a Serivce that enforces different VLANs based on the authentication and user, but then in IAP when I choose VLAN assignment Dynamic I have to make a rule based on some attribute from Clearpass and choose what VLAN that user goes in to.

    So then I have configured the VLAN on two places. This doesn't seem right. Is it possible to only configure the VLAN assignment in Clearpass?

     

    I guess the option is to have Clearpass enforce a role to the user and in IAP make a VLAN rule that say "if role = X, send to VLAN Y". But I rather do all that kind of config in Clearpass.

     

    Regards

    Philip

     



  • 2.  RE: IAP + ClearPass and dynamic VLAN

    EMPLOYEE
    Posted Mar 30, 2017 02:56 PM

    You would typically return the Aruba-User-Vlan radius attribute in your enforcement profile on ClearPass to set the VLAN for that user.



  • 3.  RE: IAP + ClearPass and dynamic VLAN

    Posted Mar 30, 2017 03:00 PM

    So then in IAP I will config: if Aruba-User-Vlan = 10, then assign VLAN 10?



  • 4.  RE: IAP + ClearPass and dynamic VLAN

    EMPLOYEE
    Posted Mar 30, 2017 03:07 PM
    You do not need any rule configuration on the Instant side. The RADIUS VSA tells the IAP what to do.


  • 5.  RE: IAP + ClearPass and dynamic VLAN

    Posted Mar 30, 2017 03:12 PM

    Oh. Then I can only have a default vlan and no other rules?



  • 6.  RE: IAP + ClearPass and dynamic VLAN
    Best Answer

    EMPLOYEE
    Posted Mar 30, 2017 03:13 PM
    If you’re returning VLANs via a RADIUS response, then you don’t need rules on the IAP.


  • 7.  RE: IAP + ClearPass and dynamic VLAN

    Posted Mar 30, 2017 03:20 PM

    That's what I wanted to hear! (read)

    Thank you verry much.