Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Do Named VLAN VSAs Work?

This thread has been viewed 4 times
  • 1.  Do Named VLAN VSAs Work?

    Posted Jun 05, 2013 03:36 PM

    I am trying to confirm wheter it is possible to use ClearPass to respond to an authentication with a named VLAN assignment?     

     

    In my Enforcement Policy/Profile I am returning the Aruba-Named-Vlan (9) attribute.  On the controller side, i have configured the server rule to look for Aruba-User-Named-Vlan and to set a value-of for VLAN assignment.      When looking at the logs, I see the proper policy/profile applicaton and ClearPass sending the attribute, but the controller reports:  

     

    Derived VLAN -1 from server rules: server-group=clearpass.radius.group 
    Assigned VLAN -1 is not configured, using default VLAN XXXX

     

    1. First, are the Aruba-User-Named-Vlan and Aruba-Named-Vlan the same; both say they are attribute #9; so I assume yes.
    2. Second, should this VSA reponse work for named VLANs?


  • 2.  RE: Do Named VLAN VSAs Work?

    Posted Jun 05, 2013 03:47 PM

    Not sure if you were able to create the vlan-name under the master controller :

     

    (master-controller) (config) #vlan-name  ?
    <name> Vlan name <1..32>

    (master-controller) (config) #vlan-name test

     

    And once you define the VLAN number under the local controller:

     

    (local-controller) (config) #vlan test ?
    <vlan-ids> List of VLAN IDs(0-removes all vlans)

     

    We were able to setup something similar using ClearPass

     

    Hope this helps.

     



  • 3.  RE: Do Named VLAN VSAs Work?

    EMPLOYEE
    Posted Jun 05, 2013 04:07 PM

    @clembo wrote:

    I am trying to confirm wheter it is possible to use ClearPass to respond to an authentication with a named VLAN assignment?     

     

    In my Enforcement Policy/Profile I am returning the Aruba-Named-Vlan (9) attribute.  On the controller side, i have configured the server rule to look for Aruba-User-Named-Vlan and to set a value-of for VLAN assignment.      When looking at the logs, I see the proper policy/profile applicaton and ClearPass sending the attribute, but the controller reports:  

     

    Derived VLAN -1 from server rules: server-group=clearpass.radius.group 
    Assigned VLAN -1 is not configured, using default VLAN XXXX

     

    1. First, are the Aruba-User-Named-Vlan and Aruba-Named-Vlan the same; both say they are attribute #9; so I assume yes.
    2. Second, should this VSA reponse work for named VLANs?

    Clembo,

     

    VLAN names in Auth, meaning being able to send back a VLAN name or pool as a VSA should be supported in 6.3.x  Please watch this space...

     

     



  • 4.  RE: Do Named VLAN VSAs Work?

    Posted Jun 05, 2013 04:12 PM

    Cjoseph 

    we currently have it working on 6.2.0.3

     

    What it will be supported in 6.3 it's VLAN name pools

     

     



  • 5.  RE: Do Named VLAN VSAs Work?

    EMPLOYEE
    Posted Jun 05, 2013 04:16 PM

    Well Vfabian,

     

    If you have it working, I would instruct Clembo on how to fix his issue, then.

     



  • 6.  RE: Do Named VLAN VSAs Work?

    Posted Jun 05, 2013 04:27 PM

     

    We wanted to have users that are part of a certain AD group using Smartphones to be place on a particular user-role and named VLAN

     

    We tied this enforcement rule to the 802.1x service 

    ClearPass Policy Manager - Aruba Networks - Google Chrome_2013-06-05_16-20-47.png

     

    We created the named VLAN CISCO-JABBER-VLAN-B on the master (not as a pool) and also created the actual user-role SECURE-VOICE-ROLE-B

     

    You don't need to create a server rule under the controller to assign that named VLAN

     

    And it's been working with no issues.

     

     



  • 7.  RE: Do Named VLAN VSAs Work?

    Posted Jun 05, 2013 11:13 PM

    Thanks for the comments guys.   The named vlans themselves have been working for a while now; being assigned by the VAP.   The setup you show Victor is similiar to what are attempting, but the named VLAN is a pool of 32 subnets.   Colin, to clarify, it is your understanding that this setup with named VLANs setup as a pool should also work in the upcoming 6.3?

     

    On a separate but related note, will there be support for assigning named vlans to user roles?  We could get around this if we could assign the named VLAN pool to the role.

     

     



  • 8.  RE: Do Named VLAN VSAs Work?
    Best Answer

    EMPLOYEE
    Posted Jun 06, 2013 07:18 AM

    Yes to all.



  • 9.  RE: Do Named VLAN VSAs Work?

    Posted Jun 13, 2013 01:04 PM