Security

Reply
Contributor II
Posts: 37
Registered: ‎05-18-2014

Clearpass, VLAN Pools, and AP Systems/Groups.

I'm looking for a way to have ClearPass put users in a specific VLAN based on their authentication source and what AP group/system their connected to. Currently, we have a setup as follows:

 

Campus 1: Faculty VLAN 21, Student VLAN 41

Campus 2: Faculty VLAN 22, Student VLAN 42

Campus 3: Faculty VLAN 23, Student VLAN 43

Campus 4: Faculty VLAN 24, Student VLAN 44

 

Faculty and Student AD sources are seperate.

Each campus has their own AP-System, and each building in each campus is an individual AP-Group.

 

I can get ClearPass to put users in their appropriate VLANs for campus 1 based on authentication source. What I realized earlier today is that I haven't considered the other campuses (this is still in a testing phase) and I'm not sure what attributes I would return in ClearPass to insure that someone connecting at campus 4 receives only the VLANs associated with campus 4.

 

Any insight would be appreciated.

Guru Elite
Posts: 7,839
Registered: ‎09-08-2010

Re: Clearpass, VLAN Pools, and AP Systems/Groups.

[ Edited ]

You can do this in a few ways.

 

  1. Different services to handle each campus
  2. Single service with rules that check for AP group and/or NAD-IP

 

 

You would create multiple VLAN enforcement profiles and return them based on your service and enforcement rules.


Tim Cappalli | Aruba ClearPass TME
@timcappalli | ACMX #367 / ACCX #480 / ACEAP / CWSP
MVP
Posts: 4,012
Registered: ‎07-20-2011

Re: Clearpass, VLAN Pools, and AP Systems/Groups.

2014-05-28 10_27_43-ClearPass Policy Manager - Aruba Networks.png

 

2014-05-28 10_30_55-ClearPass Policy Manager - Aruba Networks.png

 

2014-05-28 10_32_35-ClearPass Policy Manager - Aruba Networks.png

 

2014-05-28 10_33_36-ClearPass Policy Manager - Aruba Networks.png

 

 

 

Thank you

Victor Fabian
Lead Mobility Engineer @ Integration Partners
AMFX | ACMX | ACDX | ACCX | CWAP | CWDP | CWNA
Contributor II
Posts: 37
Registered: ‎05-18-2014

Re: Clearpass, VLAN Pools, and AP Systems/Groups.

It looks like I'll need to rewrite some rules but I think I get the direction that I need to head in. Will pop back in if I run into issues.

 

Incredibly quick and helpful responses from both of you!

Search Airheads
Showing results for 
Search instead for 
Did you mean: