Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass guest login question/issue

This thread has been viewed 1 times
  • 1.  ClearPass guest login question/issue

    Posted May 10, 2018 09:05 AM

    I have ClearPass setup to accept guest logins and social logins from Facebook, Instagram and Twitter.

     

    All works great from APs connected to my master controller. This is the controller whose name I put into the Address Field on my web login page in ClearPass Guest.

     

    If an AP is connected to one of my other controllers, it will fail after authenticating with the social network. I believe that's because it tries to hit my master controller at https://<master-controller>/login and that is not where it was originally redirected from and something freaks out.

     

    If I change the Address Field in ClearPass to my other controller, it works fine for APs connected to that controller.

     

    I'm guessing I missed something in the setup?

     

    I'm on Aruba OS 6.5.4.2 on my controllers and ClearPass 6.7.3.x

     

    Any help would be appreciated. Thanks.



  • 2.  RE: ClearPass guest login question/issue
    Best Answer

    EMPLOYEE
    Posted May 10, 2018 10:09 AM

    ClearPass web login should be configured with the controller's captive portal certificate common name. That certificate should be install on all controllers.



  • 3.  RE: ClearPass guest login question/issue

    Posted May 10, 2018 02:12 PM

    Thanks for the reply.

     

    Should I generate a new cert, not using the controller(OpenSSL or something), or can I import the already existing certificate into the other controllers?

     

    Thanks.



  • 4.  RE: ClearPass guest login question/issue

    Posted May 11, 2018 10:28 AM

    Old cert would not work, I created a new one and loaded on both controllers.

     

    Thanks.