Security

Reply
Contributor II
Posts: 43
Registered: ‎12-14-2011

Clearpass for wired devices doing mac auth or Self Reg

Hi

 

I am configuring some kit for an install we have next week. We are setting up Clearpass and some Brocade switches to hopefully do the following:

 

When a wired user plugs into the network, they are in a default VLAN 10. This does mac authentication against the endpoint database. If it is successful, then they are allowed on the network.

 

If it fails, the switch puts the device in to VLAN 40, a 'quarantine' VLAN. The idea then is that they are given the self-reg page of CPPM Guest, which they authenticate using. From there, we need to place them into a different ‘Guest’ VLAN.

 

However, the web auth doesn’t send a mac address and also can’t seemingly have an enforcement policy that can return a radius response to move the VLAN to the Guest VLAN

 

Any ideas on how we get a webauth to send a radius accept to change the VLAN? Or any ideas how we can do the above in a different way?

 

Thanks

 

Guru Elite
Posts: 8,456
Registered: ‎09-08-2010

Re: Clearpass for wired devices doing mac auth or Self Reg

[ Edited ]

You can set a post_authentication Change of Authorization (RADIUS CoA) which will boot the user (essentially aaa user delete) and then they will come back into the role you assigned.


Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Contributor II
Posts: 43
Registered: ‎12-14-2011

Re: Clearpass for wired devices doing mac auth or Self Reg

CoA isn't supported on Brocade.......:smileysad:

Contributor II
Posts: 43
Registered: ‎12-14-2011

Re: Clearpass for wired devices doing mac auth or Self Reg

Actually just gave this a try anyway but CPPM said nothing was output anyway.

Regular Contributor I
Posts: 159
Registered: ‎03-03-2011

Re: Clearpass for wired devices doing mac auth or Self Reg

Did you ever get this working on Brocade?

Regards,

Josh
___________
ACMP, ACCP
Search Airheads
Showing results for 
Search instead for 
Did you mean: