Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass - Guest Network and NAD IP address

This thread has been viewed 46 times
  • 1.  ClearPass - Guest Network and NAD IP address

    Posted Jul 11, 2017 04:47 PM

    Hi everyone,

     

    Just a quick question. When creating a web login page in ClearPass there is a field "Address":

    guestnetworknadipaddress.PNG

    The description says "Enter the IP address or hostname of the vendor’s product here.". By default it is set to securelogin.arubanetworks.com. Is this the NAD IP address? Because in my case my controller IP address is 192.168.1.96, but with the default setting I can access the web login page successfully. What am I missing?

     

    Regards,

    Julián



  • 2.  RE: ClearPass - Guest Network and NAD IP address

    EMPLOYEE
    Posted Jul 11, 2017 04:49 PM

    No, it needs to be set to the common name of your controller/IAP captive portal certificate.



  • 3.  RE: ClearPass - Guest Network and NAD IP address

    Posted Jul 11, 2017 06:01 PM

    OK thanks, then this description is a little bit confusing.

     

    Regards,

    Julián



  • 4.  RE: ClearPass - Guest Network and NAD IP address

    Posted Jul 12, 2017 10:16 AM

    Hi Tim,

     

    Please a couple of two more questions about this:

     

    1. Why does it need to be set to the CN of my controller captive portal certificate if I am using ClearPass? The captive portal process happens in ClearPass and not in the controller.

     

    2. What does securelogin.arubanetworks.com mean exactly? If I issue a nslookup for that name no IP address is returned so how can the client reach https://securelogin.arubanetworks.com?

     

    Regards,

    Julián



  • 5.  RE: ClearPass - Guest Network and NAD IP address

    EMPLOYEE
    Posted Jul 12, 2017 10:32 AM

    1. The client needs to submit the captive portal form to that "virtual name" which is generated based on the common name of the certificate. The controller then generates a RADIUS request to the RADIUS server (ClearPass).

     

    2. securelogin.arubanetworks.com is filler text. This needs to replaced with the CN of your captive portal certificate.



  • 6.  RE: ClearPass - Guest Network and NAD IP address

    Posted Mar 31, 2020 12:27 AM

    @cappalli wrote:

    1. The client needs to submit the captive portal form to that "virtual name" which is generated based on the common name of the certificate. The controller then generates a RADIUS request to the RADIUS server (ClearPass).


    Does the common name need to relate to the anything meaningful? For example, if I used captiveportal-login.mydomain.com, do I need a DNS record for captiveportal-login.mydomain.com or login.mydomain.com?



  • 7.  RE: ClearPass - Guest Network and NAD IP address

    EMPLOYEE
    Posted Mar 31, 2020 01:30 AM

    You don't need a DNS entry for this. The controller will intercept the DNS request and respond with the correct IP for the controller. Just make sure you install the certificate properly on the controller and assign it as "captive portal certificate" on the controller.



  • 8.  RE: ClearPass - Guest Network and NAD IP address

    Posted Mar 31, 2020 01:35 AM
    Thanks for the speedy reply!

    What is the purpose of the certificate? Is it to authenticate the
    controller to clearpass?


  • 9.  RE: ClearPass - Guest Network and NAD IP address

    EMPLOYEE
    Posted Mar 31, 2020 01:54 AM

    Hi,

     

    Check this guide that explains the flow..

     

    In brief, after the client logins succesfully to Clearpass Guest page, ClearPass instructs the client browser to submit the credentials to the controller. This is where the certificate on controller will be needed. The controller then initiates a RADIUS request to ClearPass (Step 5)

    https://community.arubanetworks.com/t5/07-19-13-Expert-Day/How-does-captive-portal-authentication-really-work-with/td-p/87208

     

    Also, you can check this video by Herman https://www.youtube.com/watch?v=_uO2-RGJ3BM It shows the packet flow step by step based on Instant APs but the same logic applies to controller.



  • 10.  RE: ClearPass - Guest Network and NAD IP address

    Posted Jan 12, 2018 03:50 AM

    Tim ... thanks this so far the simplest and the best answers to this question ... seriously

     

    and by the way u can use a wildcard cert at CTRL  (*.mydomain.com)

    In this case IP Address field should looks like:

     

    captiveportal-login.mydomain.com