Security

last person joined: 20 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

BYOD Setup SSID Webpage redirection

This thread has been viewed 1 times
  • 1.  BYOD Setup SSID Webpage redirection

    Posted Sep 26, 2013 04:15 PM

    I am trying to create an SSID, that forces all users to land on an external wepage that gives users information regarding BYOD and how to setup their devices.  So far I have created the open SSID, and have created a rule with dst-nat to my external web server, but it doesn't work well.  Shortcuts on browsers are causing weird errors from my webserver because the url doesn't exist and ssl doesn't seem to work well either.  Any ideas?  I thought this would be simple (and maybe it is) but I am hitting some bumps here.  Thanks for any help.



  • 2.  RE: BYOD Setup SSID Webpage redirection

    Posted Sep 26, 2013 04:23 PM

    Could you not just a set a rule to give access to the external web server.

    Then configure the 'Captive Portal' for your default User Profile for your SSID. Your 'Captive Portal' would point to the URL of your external web server

     

    Aruba_CaptivePortal.png

     

    I think this should work anyway I could be missing something more obvious!



  • 3.  RE: BYOD Setup SSID Webpage redirection

    EMPLOYEE
    Posted Sep 26, 2013 04:25 PM
    What types of browser errors are you seeing?


  • 4.  RE: BYOD Setup SSID Webpage redirection

    Posted Sep 26, 2013 04:57 PM

    The way i have it configured right now, it seems the dst-nat rule is doing most of the work, but that is not overwriting the url, it just changes the destination ip, so someone going to www.google.com/something/whatever.php, it changes it to http://IPADDRESS-OF-MY-SERVER/something/whatever.php.  I guess I could do some sort of rewrite rule on apache worl work.  Still https issues, my guess is because of certificates showing wrong somain vs the certificate.  Also deosn't help that i don't yet have a certificate on the webserver yet.  If I can get http working correctly, I figure https will follow.



  • 5.  RE: BYOD Setup SSID Webpage redirection

    Posted Sep 26, 2013 04:45 PM

    I've tried just that.  I have an access rule that allows to my web server.  I have captive portal login page set as the web address of my server, but that does not force a redirect.  So when someones browser comes up, it just stalls on whatever page it is trying to load.



  • 6.  RE: BYOD Setup SSID Webpage redirection

    EMPLOYEE
    Posted Sep 26, 2013 04:48 PM
    Does the controller have a layer 3 interface in the VLAN that the user's
    are in? This is required for redirection.


  • 7.  RE: BYOD Setup SSID Webpage redirection

    Posted Sep 26, 2013 05:00 PM

    It does... in fact the vlan that users are being placed into is a natted network.



  • 8.  RE: BYOD Setup SSID Webpage redirection

    Posted Sep 26, 2013 11:43 PM

    Make sure DNS and http/https is allowed  , you should run the following command to make sure nothing is getting blocked : show datapath session table <client ip address>

     

    Confirm that you have configured the Captive portal profile under the user-role you have setup for your initial role

     

    Security User Roles_2013-09-26_23-40-12.png

     

     



  • 9.  RE: BYOD Setup SSID Webpage redirection
    Best Answer

    Posted Sep 27, 2013 02:58 PM

    I did finally get it to work.  The main problem seemed to be the order of policies in the user role I had defined.  I had to put the http and https allow for my external web server above the captive portal policy.  After that it worked like buttah!



  • 10.  RE: BYOD Setup SSID Webpage redirection

    Posted Sep 30, 2013 09:03 AM

    RMorely, 

    do you have the users authenticate at all (and thus change user group) or they stay "unauthenticated" with limited access just to the webserver?

    Do you have also have an ACL to block all other traffic to everywhere else appart from your web-server?

     

    Thanks



  • 11.  RE: BYOD Setup SSID Webpage redirection

    Posted Sep 30, 2013 11:43 AM

    No authentication going on here.  This is simply for staff and students who bring personal devices to school to get info on how to connect to our 802.1x network.  I also have an su1x install that configures windows 7 and xp that they can download from the website, since I did not want to pay for arubas quick connect.  The user role only allows them to connect to this particular website.