Security

Reply
Occasional Contributor I
Posts: 6
Registered: ‎08-05-2015

Airgroup and Clearpass

We had Airgroup working with CPPM forced registration turned on. We have Chromecast devices throughout our district and want to limit what users can see and have access to. We recently added a captive portal with Google Authentication so we create a Cluster for our Master and Local Controller with a VIP.  We also have our AP groups load balanced to both the Master and Local.

After making the changes the forced registration prevents users from seeing any chromecasts. If I disable the forced registration they will show up.

Any thoughts?

Guru Elite
Posts: 8,759
Registered: ‎09-08-2010

Re: Airgroup and Clearpass

- Are you seeing the AirGroup Authorizations in ClearPass Access Tracker?

- Are you seeing the server entries on the controller with the command:

show airgroup cppm entries

- Did a partner set this up for you?


Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Occasional Contributor I
Posts: 6
Registered: ‎08-05-2015

Re: Airgroup and Clearpass

I am seeing the AirGroup Authorizations in Clearpass.

I am seeing the server entries on the Local Controller but not the Master Controller. Since the AP-Groups terminate on different controllers I need to look on both.

I did have a partner set it up and they could not figure out why it was not working. They suggested I put in help request with Aruba and they were not able to figure it out either.

Guru Elite
Posts: 21,491
Registered: ‎03-29-2007

Re: Airgroup and Clearpass

Load balancing APs between two controllers could be your issue.  I am sure that does create a variable.  Users probably should not be allowed to roam between controllers in a regular deployment.



Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Occasional Contributor I
Posts: 6
Registered: ‎08-05-2015

Re: Airgroup and Clearpass

[ Edited ]

I will terminate them all on one controller. Which controller would be ideal? The Master or Local? Also, should I have an Active AirGroup Domain setup?

- Thank you for your quick response.

Guru Elite
Posts: 8,759
Registered: ‎09-08-2010

Re: Airgroup and Clearpass

You should only see them on the local controller where the AP is
terminating. You may want to open a TAC case.

Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Occasional Contributor I
Posts: 6
Registered: ‎08-05-2015

Re: Airgroup and Clearpass

I will open another case. The following is the message I see when I am in the Aruba - Dashboard - Airgroup and looking at a client.

server registration is required but server is not registered in CPPM/Controller

All of my AirGroup servers are in Clearpass Manage Devices and are shared devices. Is there anything on the Clearpass side that I am missing?

 

screenshot-10.1.71.221 4343 2016-08-17 14-45-34.png

 

 

MVP
Posts: 129
Registered: ‎07-13-2015

Re: Airgroup and Clearpass

Are the 2 controllers added in Clearpass guest under Administration -­> Airgroup Services -> Controllers ?

If you press the read configuration button when selecting one, is it working ?

ACMP, ACCP, BCNE
Guru Elite
Posts: 8,759
Registered: ‎09-08-2010

Re: Airgroup and Clearpass

Which controller is that from?

Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Occasional Contributor I
Posts: 6
Registered: ‎08-05-2015

Re: Airgroup and Clearpass

Both Controllers are added in Clearpass and the Read Configuration button is working.

Search Airheads
Showing results for 
Search instead for 
Did you mean: