Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

API-205 and PacketFence

This thread has been viewed 2 times
  • 1.  API-205 and PacketFence

    Posted Apr 27, 2015 06:01 AM

    hey all,

     

    I am using a API-205 and PacketFence ZEN version as external Captive Portal.

     

    Now I want to connect them with Inline Enforcement and over the Virtual Controller of the Access Point.

     

    If I try to connect to the WLAN on my phone I get redirected to the portal and I'm also able to login, but after the login I still got no connection to the internet.

     

    Does anyone have a clue how I need to configure the AP or is the problem maybe on the PacketFence configuration?

     

    Regards,

     

    SJS



  • 2.  RE: API-205 and PacketFence

    Posted Apr 27, 2015 07:23 AM

    Hi,

     

    After login is the user in a role on the Instant web interface that should allow internet access?

     

    Might well be a packetfence issue....

     

    Cheers

    James



  • 3.  RE: API-205 and PacketFence

    Posted Apr 27, 2015 08:15 AM

    No the user is still in the wrong Role.

    I made 2 Roles one for preAuth and one after which is the standard Role, but the user is still in the preAuth Role.

     

    The standard role is the one with internet access.

     

    Regards,

     

    SJS

     



  • 4.  RE: API-205 and PacketFence

    Posted Apr 27, 2015 10:14 AM
      |   view attached

    hi,

     

    I found the configuration file from my API-205, it's in the attachment.

     

    And on the PacketFence I made under Configuration -> Switches a switch:
    IP: 192.168.12.3 (from the virtual controller)
    Type: Aruba 200 Controller
    Mode Production
    Deauthentucation Method: RADIUS
    Dynamic Uplinks: active
    Inline mode if any of the following conditions are met: always
    Radius Passphrase: Same as on the Access Point

     

    And the rest is on default.

     

    maybe this will help :)

     

    Cheers,
    SJS

    Attachment(s)

    txt
    aruba.txt   468 KB 1 version


  • 5.  RE: API-205 and PacketFence

    Posted Apr 27, 2015 11:14 AM

    Hi,

     

    Have you configured role mapping on switch configuration on the PacketFence? I don't know much about PacketFence but I'm assuing you'll need to configure the "Role by Switch Role" section in your switch config.

     

    To me it soundsmore like a PacketFence config issuerather than something on your Instant config.

     

    Cheers

    James