Controllerless Networks

last person joined: 14 hours ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

Instant vs Clearpass Guest

This thread has been viewed 1 times
  • 1.  Instant vs Clearpass Guest

    Posted Oct 03, 2012 05:21 AM

    Hello everybody,

    did someone succeed to get Instant working against Clearpass Guest as external CP?

     

    I did follow instructions in Instant User Guide_6.1.3.1-3.0.0.0.pdf , and when client connects it gets redirected Clearpass, however then Firefox will say "Connection Interrupted"...see screenshot. (From Internet Explorer  I will get "IE can't display this web")

    From Instant perspective client is stuck in "External CP" role.

     

    My impression is that there is proxy in Instant which is misbehaving (e.g. in this state I can display www.microsoft.com but www.google.com get's me "Invalid browser request" page)

     

    Instant version: 6.1.3.4-3.1.0.0_35320

    Clearpass version: 3.9

     

    By the way, is there some detailed manual for this scenario?

     

     



  • 2.  RE: Instant vs Clearpass Guest

    EMPLOYEE
    Posted Oct 03, 2012 06:36 AM

    In your instant role, are you allowing http, https to the clearpass server?

     



  • 3.  RE: Instant vs Clearpass Guest

    Posted Oct 03, 2012 08:07 AM

    "Access Rules" for this SSID is set to "Unrestricted" which I assume is equivalent of Allow all...



  • 4.  RE: Instant vs Clearpass Guest

    EMPLOYEE
    Posted Oct 03, 2012 08:13 AM

    In the clearpass-page.jpg you have the address parameter as clearpass-guest.showroom.cz but it should be the ip address of the virtual controller, NOT the URL of the clearpass guest appliance.



  • 5.  RE: Instant vs Clearpass Guest

    Posted Oct 03, 2012 10:07 AM
      |   view attached

    OK, you're right with address field!

     

    But turn's out there was a bigger problem before that.

    In Clearpass I had to disable first https for NAS and htttps for Clearpass login. Then I'm able to autheticate over Instant successfully.

     

    Question is, how can I get it running with https?

     

    Seems then client tries to open SSL twice but somehow fails. Interestlingly when client uses SSID without external CP, it has no problems opening https:// on Clearpass so it must be CP related...

     

    Trace attached...

    Attachment(s)

    zip
    trace4.zip   2 KB 1 version