Security

last person joined: 20 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Guest not access to captive portal

This thread has been viewed 0 times
  • 1.  Guest not access to captive portal

    Posted Jul 20, 2015 10:43 PM

    I installed clearpass CPPM and guest module and I configured everything by after I try to connect SSID, it redirect to captive portal but there's alert that "the page contains too many server redirects"

     

    I configure redirect page as http://10.10.1.93/guest/guest_register.php

    and has firewall policy to allow captive portal

     

    Capture.JPGCapture.JPG

     

    Capture.JPG



  • 2.  RE: Guest not access to captive portal

    EMPLOYEE
    Posted Jul 20, 2015 10:45 PM

    Please post the output of:

    show rights <captive-portal-role>


  • 3.  RE: Guest not access to captive portal

    Posted Jul 20, 2015 10:54 PM

    Derived Role = 'G-guest-logon'
    Up BW:No Limit Down BW:No Limit
    L2TP Pool = default-l2tp-pool
    PPTP Pool = default-pptp-pool
    Periodic reauthentication: Disabled
    DPI Classification: Enabled
    ACL Number = 83/0
    Max Sessions = 65535

    Captive Portal profile = G-cp_prof

    Application Exception List
    --------------------------
    Name Type
    ---- ----

    Application BW-Contract List
    ----------------------------
    Name Type BW Contract Id Direction
    ---- ---- ----------- -- ---------

    access-list List
    ----------------
    Position Name Type Location
    -------- ---- ---- --------
    1 global-sacl session
    2 apprf-G-guest-logon-sacl session
    3 captiveportal session
    4 logon-control session

    global-sacl
    -----------
    Priority Source Destination Service Application Action TimeRange Log Expired Queue TOS 8021P Blacklist Mirror DisScan ClassifyMedia IPv4/6 Contract
    -------- ------ ----------- ------- ----------- ------ --------- --- ------- ----- --- ----- --------- ------ ------- ------------- ------ --------
    apprf-G-guest-logon-sacl
    ------------------------
    Priority Source Destination Service Application Action TimeRange Log Expired Queue TOS 8021P Blacklist Mirror DisScan ClassifyMedia IPv4/6 Contract
    -------- ------ ----------- ------- ----------- ------ --------- --- ------- ----- --- ----- --------- ------ ------- ------------- ------ --------
    captiveportal
    -------------
    Priority Source Destination Service Application Action TimeRange Log Expired Queue TOS 8021P Blacklist Mirror DisScan ClassifyMedia IPv4/6 Contract
    -------- ------ ----------- ------- ----------- ------ --------- --- ------- ----- --- ----- --------- ------ ------- ------------- ------ --------
    1 user controller svc-https dst-nat 8081 Low 4
    2 user any svc-http dst-nat 8080 Low 4
    3 user any svc-https dst-nat 8081 Low 4
    4 user any svc-http-proxy1 dst-nat 8088 Low 4
    5 user any svc-http-proxy2 dst-nat 8088 Low 4
    6 user any svc-http-proxy3 dst-nat 8088 Low 4
    logon-control
    -------------
    Priority Source Destination Service Application Action TimeRange Log Expired Queue TOS 8021P Blacklist Mirror DisScan ClassifyMedia IPv4/6 Contract
    -------- ------ ----------- ------- ----------- ------ --------- --- ------- ----- --- ----- --------- ------ ------- ------------- ------ --------
    1 user any udp 68 deny Low 4
    2 any any svc-icmp permit Low 4
    3 any any svc-dns permit Low 4
    4 any any svc-dhcp permit Low 4
    5 any any svc-natt permit Low 4
    6 any 169.254.0.0 255.255.0.0 any deny Low 4
    7 any 240.0.0.0 240.0.0.0 any deny Low 4

    Expired Policies (due to time constraints) = 0

     

     

    Thank you for fast reply



  • 4.  RE: Guest not access to captive portal
    Best Answer

    EMPLOYEE
    Posted Jul 20, 2015 10:57 PM

    You need to allow your ClearPass servers. Go to Configuration > Stateful Firewall > Destinations and add a destination called CLEARPASS. Add in your ClearPass IPs.

     

    Now go to your captive portal profile (under L3 authentication), find the Whitelist option and select the netdestination you just created and add it.