Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM integration with Ruckus

This thread has been viewed 29 times
  • 1.  CPPM integration with Ruckus

    Posted Mar 15, 2017 09:56 AM

    Hi!

     

    I'm trying to integrate CPPM with Ruckus Wireless solutions and Dell Switching solutions.

     

    So, I have some questions to ask:

     

    802.1x with Dell Switches = Works fine, just need to known if I can redirect users to Onguard portal with some url redirect.

     

    802.1x with Ruckus Wireless = Can't authenticated users with 802.1x. I follow the same setup as an IAP, with some changes to compliance with Ruckus. On IAP works fine, but when a use Ruckus, the client shows authenticated on CPPM (so, Services are correctly configured) but still can't connect on network.

     

    Onboard with Ruckus Wireless = I use the option of two SSIDs, one for Onboard and another for clientes Onboarded. On SSID Onboard, I configure the captive portal device_privisioning.php and the user can install the certificate/profile. When the user tries to connect on SSID Onboarded, I stuck because the same problem with 802.1x.

     



  • 2.  RE: CPPM integration with Ruckus

    EMPLOYEE
    Posted Mar 15, 2017 09:58 AM

    - What model Dell switches?

    - Please post screenshots of your configuration

    - Have you reached out to your Aruba Clearpass partner?



  • 3.  RE: CPPM integration with Ruckus

    Posted Mar 15, 2017 10:24 AM
      |   view attached

    Hi, thanks for your response.

     

    - What model Dell switches?

    Dell Switches N3000 Series and Powerconnect Series.

     

    - Please post screenshots of your configuration

    Follow attached.

     

    - Have you reached out to your Aruba Clearpass partner?

    Yes, they are researching internally with the team.

     

    I download the Clearpass POC Kit and I can't see any documentation to use CPPM with Ruckus.

     

     



  • 4.  RE: CPPM integration with Ruckus

    EMPLOYEE
    Posted Mar 15, 2017 10:33 AM

    Unforutnately I don't have a Dell N-series switch to test with but from a quick glance at their docuemtnation, they don't appear to support external captive portal redirect. In this case, you would need to use their internal captive portal and point the authentication piece to ClearPass, or you'd need to investigate using wildcard DNS if external redirect to ClearPass is required.

     

    For Ruckus, they should be accepting a generic IETF Access-Accept message. What do the logs on the Ruckus controller show?



  • 5.  RE: CPPM integration with Ruckus

    Posted Mar 15, 2017 03:28 PM

    Well, this is weird.

     

    At Ruckus Controller I see the message:

    User[d4:f4:6f:a1:e9:7c] failed to log in. No permission or incorrect credentials.

     

    With this same credentials I can authenticate on IAP.

     

     

    PS.: This settings may be different from screenshoot I post because now I'm testing in my lab environment.

    Attachment(s)

    txt
    Dashboard_Details.txt   2 KB 1 version
    txt
    Clearpass-LogAuth.txt   16 KB 1 version


  • 6.  RE: CPPM integration with Ruckus

    Posted Mar 16, 2017 09:36 AM

    Hi!

     

    someone?



  • 7.  RE: CPPM integration with Ruckus

    Posted Mar 16, 2017 11:58 AM

    Hello,

     

    Just an update. I've got this logs from Ruckus, CPPM and a Packet Capture from Ruckus to CPPM.

     

    PS: Just rename the PacketCapture.png to PacketCapture.pcap

    Attachment(s)

    txt
    CPPM-Outputs_11-45.txt   2 KB 1 version
    txt
    RUCKUS-EventLog.txt   609 B 1 version


  • 8.  RE: CPPM integration with Ruckus
    Best Answer

    Posted Mar 17, 2017 08:12 AM

    Well, I found a KB article at Ruckus Support that solve my problem. And, it's simple.

     

    Question
    User [MAC address of the Client] failed to log in. No permission or incorrect credentials.'
     
    Resolution

    The solution to resolve the issue when we see the ;og 'User [MAC address of the Client] failed to log in. No permission or incorrect credentials.':

    When we see the below logs in the ZD GUI::Monitor::All Events/Activities, we need to check whether the WLAN to which the user is connecting has been checked in the default role list or not. If the WLAN haven't checked in the default Role list we get the below error.

    User [MAC address of the Client] failed to log in. No permission or incorrect credentials.

    User [MAC address of the Client] failed to log in. No permission or incorrect credentials.

    User [MAC address of the Client] failed to log in. No permission or incorrect credentials.

    User [MAC address of the Client] failed to log in. No permission or incorrect credentials.

    When the users are connecting they will be assigned to “Default” role and if they do not see that the specific WLAN in the default Role list then it throws a above message, so please make sure that you select all the WLANs in the default role of the Zone Director. To configure that --> please go to ZD GUI::Configure::Roles:: 'Default' Role and select radio button for 'Allow access to all WLANs' and save it.



  • 9.  RE: CPPM integration with Ruckus

    Posted Apr 10, 2017 06:20 AM

    Is it possible to Integrate Aruba Clearpass with Ruckus SmartZone 100 Virtual Controller ? please share me the documentation for this integration.

    Thanks

     

    Rgds,
    Jefri

     



  • 10.  RE: CPPM integration with Ruckus

    Posted Aug 14, 2019 02:46 PM

    Hi Jefri,

     

    Did you find an answer about this integration?

     

    Regards

     

    N3tw0rk3r



  • 11.  RE: CPPM integration with Ruckus

    Posted Aug 14, 2019 03:02 PM

    ClearPass will integrate with any vendor, even the coffee machine if you want to.

     

    Documentation about Ruckus you can see at they website.

     

    ClearPass will be just the Radius Server that will authenticate clients using 802.1X, MAC-AUTH. If you want to know about Captive Portal, you can use the documentation provided by Ruckus to integrate with external captive portals.