Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Cluster and Guest Captive Portal

This thread has been viewed 10 times
  • 1.  ClearPass Cluster and Guest Captive Portal

    Posted Nov 23, 2016 03:55 AM
    Hi
    We have 2 node CPPM cluster in the US. Publisher near the west coast and Subscriber near the east coast. We want to set up the system in such a way that we can run a captive portal on each appliance so that we can keep the user traffic local to the area. Can you run a captive portal on a Subscriber, I didn't think you could? We don't want users based in New York have to authenticate to the appliance in California, and vice versa, if you get the idea?
    Many Thanks


  • 2.  RE: ClearPass Cluster and Guest Captive Portal

    Posted Nov 23, 2016 06:53 AM

    Yes, you can use the web logins/registration pages of CPPM Guest on any appliance in the cluster.   You need to configure your access devices (wireless controllers, switches, etc.) to point to the appropriate instance of CPPM.

     

    However, keep in mind, if you use the registration features, although your clients will hit a web page on the subscriber, the actual process of creating the user/device is done on the publisher.



  • 3.  RE: ClearPass Cluster and Guest Captive Portal

    Posted Nov 23, 2016 02:17 PM
    Thanks. So sounds like Guest Self Reg is only available on the active publisher. But once created, the Subscriber could handle those authentications?
    Rgds


  • 4.  RE: ClearPass Cluster and Guest Captive Portal

    Posted Nov 23, 2016 04:38 PM

    You can host the portal on either the PUB or the SUB. The account creation [writing to the DB] always happens on the PUB and the account info then being sync to the SUB, the SUB would then authN the user locally.



  • 5.  RE: ClearPass Cluster and Guest Captive Portal
    Best Answer

    Posted Nov 24, 2016 10:21 AM

    OK thats great, many thanks