Security

Reply
New Contributor

Clearpass and Meraki

Hi all

 

I have a network build with meraki access points supported by clearpass policy server.

 

I got guest and 802.1X working, 

Last week meraki added CoA to the radius settings.

I would like to use this in my posturing but can not figger out how to add the meraki radius attributes.

 

Does somebody have any pointers?

New Contributor

Re: Clearpass and Meraki

I have the exact same problem.  I have the Meraki SSID using WPA2-Enterprise against Clearpass Policy Manager.  Based on the criteria and AD groups clearpass sends back the correct Filter-ID in the radius accept message, that will dynamically aply the appropriate Meraki security policy.  However, I am struggling to figure out how I can change the security policy after CPPM and the OnGuard agent finish their checks.  Any feedback on how to do this?

Occasional Contributor I

Re: Clearpass and Meraki

What do you want to use a change of authorization to do exactly? Based on Meraki Documentation, you can only do reauthenticate and disconnect request.  If you need to send radius attributes you can setup an enforcement profile to handle the specific criteria.  For example, I am using radius private-tunnel-id to set the vlan based on user or machine auth.  

 

Hope that helps. 

Occasional Contributor I

Re: Clearpass and Meraki

I am new to Clearpass, and i am trying to setup something similiar to yours.  Is their documentation you followed to set this up with Meraki?  Thanks

Occasional Contributor I

Re: Clearpass and Meraki

Brad-  Can you tell me what you are looking to do? 

If you are setting up api calls I will be working on documenting the process.  I will most likely share that with Meraki so they can add it to their documentation. 

If you just need to tag a vlan you can us an enforcement profile.  It is all radius ietf settings.

 

 

Occasional Contributor I

Re: Clearpass and Meraki

As of right now we are just wanting to implement a simple service where, any new device cannot connect to the Network untill we mark it as a known device.  All Unknown and disabled devices will not be able to connect.  So users will authenticate against the local user Repository, then their device will need to be known.  I believe i have this working now with The local user repository as the Authentication Soruce, the Endpoint Repository as the Authorization source and then Enforcment Policy rules For Unknown and Disabled Devices set to the Deny Access Profile.  Not sure if this is the best way to accomplish it, but it seems to be working.

Occasional Contributor I

Re: Clearpass and Meraki

Are you profiling endpoints?  That may be the easiest way to get them in the endpoints database.  Basic idea is to enable profiling and point an ip-helper to the ClearPass server. That will start profiling any device doing DHCP. 

New Contributor

Re: Clearpass and Meraki

Hi,

 

Do you know if I can enforce dynamic url-redirect to a remediation quarantine captive portal in case there is an 'unhealty status' result for a posture check (either persitent or dissolvable agent)?

Guru Elite

Re: Clearpass and Meraki

Yes. The standard Cisco url-redirect can be used.

Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
New Contributor

Re: Clearpass and Meraki

We're working to use Clearpass with Meraki and cannot seem to get the service working.  Basically, we have 2 SSID's that require authentication, we want to limit devices owned by our institution to connect to a specific SSID.  Our Meraki devices assign the VLAN, so is it possible that the 802.1x request includes the SSID + device is in the repository + valid credential would allow the person to connect?

 

We've been using Clearpass for NAC in labs but would like to consolidate all our RADIUS to Clearpass.

Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: