Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM Radius with LDAP question

This thread has been viewed 1 times
  • 1.  CPPM Radius with LDAP question

    Posted Oct 02, 2017 07:06 AM

    Hi,

     

    I have an Aruba Controller and a CPPM. I need to know if it is possible to configure this scenario:

     

    - Configure a Radius server (CPPM) inside Aruba controller.

    - Create a captive portal inside CPPM where users will must be enter user/pass.

    - Once CPPM receives the user/pass introduced by users trhough CPPM's Captive Portal, It has to verfy it against an external LDAP server.

     

    I need set the configuration flow of this scenario.  Could you help me?

     

    Regards

     

     



  • 2.  RE: CPPM Radius with LDAP question

    EMPLOYEE
    Posted Oct 02, 2017 07:36 AM
    What specifically do you need help with? This is a pretty standard setup.


  • 3.  RE: CPPM Radius with LDAP question

    Posted Oct 02, 2017 07:47 AM

    Thank you for your reply.

     

    I need to configure a SSID in the Aruba controller where users will be redirected to a captive portal inside CPPM to enter user and pass. To make it I understand that I have to:

     

    - Creat a Captive Portal auth profile

    - A server group

    - Configure inside server group a Radius Server (CPPM)

    - An user role

    - A captive portal aaa profile

     

    And at the end, associate all this profiles and roles to the SSID created on the Aruba Controller.

     

    (Correct me If I'm wrong)

     

    I need to know the configuration flow to configure the CPPM, I need that:

     

    - Captive portal configured inside it.

    - Controller association

    - Once the controller init the authentication with its radius server (CPPM) and users have entered their credentials, I need that CPPM check this user/pass against an external LDAP server.