Security

Reply
MVP
Posts: 366
Registered: ‎01-14-2010

Cisco WLC + Clearpass with a specific Radius attribute

All,

 

This is driving me crazy, and I know it's a small thing. I'm working on a project integrating some Cisco WLCs with Clearpass and all of the WLCs, except one, are sending a RADIUS attribute to Clearpass.

 

In Access Tracker, I'm receving a RADIUS attribute called:

 

Connection : SSID : <SSID name>

 

from 95% of the controllers. The other controller is not sending that RADIUS information, so I'm using the Called Station ID instead.

 

I'd like to make the Clearpass config as uniform as possible without having to have a separate clause just for this one WLC. Any chance someone has run into this before and figured it out?


Thanks for the help!

 

-Mike

Guru Elite
Posts: 8,027
Registered: ‎09-08-2010

Re: Cisco WLC + Clearpass with a specific Radius attribute

[ Edited ]

Mike I think Connection : SSID is a computed attribute not a direct RADIUS response. Are you able to do a packet capture and see what looks different between the RADIUS requests?

You can do a packet capture right from ClearPass now:
Administration > Server Manager > Server Configuration then click on the server name and hit Collect Logs and uncheck everything but “Capture network packets”


Sent from Surface Pro


Tim Cappalli | Aruba ClearPass TME
@timcappalli | ACMX #367 / ACCX #480 / ACEAP / CWSP
MVP
Posts: 4,114
Registered: ‎07-20-2011

Re: Cisco WLC + Clearpass with a specific Radius attribute

All WLCs running the same code ?
Thank you

Victor Fabian
Lead Mobility Engineer @ Integration Partners
AMFX | ACMX | ACDX | ACCX | CWAP | CWDP | CWNA
MVP
Posts: 4,114
Registered: ‎07-20-2011

Re: Cisco WLC + Clearpass with a specific Radius attribute

[ Edited ]

You could use the  airspace WLAN ID number

 

250760.jpg

 

2014-06-05 22_15_46-ClearPass Policy Manager - Aruba Networks.png

 

2014-06-05 22_17_31-ClearPass Policy Manager - Aruba Networks.png



In access tracker > input , you should be able to get this information and use it in the service to distinguish each

 

 

Thank you

Victor Fabian
Lead Mobility Engineer @ Integration Partners
AMFX | ACMX | ACDX | ACCX | CWAP | CWDP | CWNA
MVP
Posts: 366
Registered: ‎01-14-2010

Re: Cisco WLC + Clearpass with a specific Radius attribute

Hi All,

 

Thanks for the replies! As of right now, they're all running the same code, 7.6.110.0. I haven't yet done a packet capture because I was hoping this would be a check box fix, haha. I'll give that a whirl next week when I'm on-site with the customer.

 

Also, unfortunately, the WLAN indices are currently different across the various controllers. That's why it would be nice to use something like the Connection SSID.

 

Thanks for all of the suggestions! 

 

-Mike

 

 

MVP
Posts: 4,114
Registered: ‎07-20-2011

Re: Cisco WLC + Clearpass with a specific Radius attribute

[ Edited ]

You could use belongs to and will WLAN ID 1 or 2

 

2014-06-13 11_20_00-ClearPass Policy Manager - Aruba Networks.png

Thank you

Victor Fabian
Lead Mobility Engineer @ Integration Partners
AMFX | ACMX | ACDX | ACCX | CWAP | CWDP | CWNA
Search Airheads
Showing results for 
Search instead for 
Did you mean: