Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass - Logical Interfaces

This thread has been viewed 4 times
  • 1.  Clearpass - Logical Interfaces

    Posted Jun 16, 2017 07:21 AM

    Hi there,

     

    We're currently using a Captive Portal for our Guest Internet connectivity which is hosted on Clearpass, which at this early stage is just using the private IP address of a VIP within Clearpass for the URL, I'm looking to make this look a little nicer by using a domain within the URL.

     

    Our issue currently is that the domain we're looking to use resolves against a Public IP address (our guest environment is using Public DNS servers) and due to company restrictions, we can't have a public facing DNS entry resolve against an internal IP address.

     

    So, I'm looking to understand if it's possible to have some sort of logical IP entry within our Clearpass infrastrcture, that will enable clients to perform a DNS lookup for the Clearpass portal URL 'guests.abcdomain.com' - Which resolves to a Public IP address, for which the Clearpass devices would reply to any traffic requests should we route the traffic for the Public IP address in to Clearpass.

     

    I've played with the idea of changing the URL so something internal, but we as we're using public DNS servers this is a non-starter. Also, within the network equipment involved in the Guest DMZ, we dont have the ability to perform any sort of network address translation. The logical interface within CPPM seems our only option at the moment.

     

    Appreciate people's thoughts.

     

    Thanks



  • 2.  RE: Clearpass - Logical Interfaces

    Posted Jun 16, 2017 07:28 AM
    If the data port is tied to the DMZ see if your firewall can do a DNS proxy only for the ClearPass guest URL

    Get Outlook for iOS


  • 3.  RE: Clearpass - Logical Interfaces

    Posted Jun 16, 2017 10:10 AM

    Unfortunately, that isn't something we'll be able to achieve using the Firewall within this environment.



  • 4.  RE: Clearpass - Logical Interfaces

    EMPLOYEE
    Posted Jun 16, 2017 10:20 AM
    Your only option would be to use views functionality on your DNS server then.