Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Internal CP to Clearpass Guest migration

This thread has been viewed 0 times
  • 1.  Internal CP to Clearpass Guest migration

    Posted Jul 09, 2014 08:41 AM

    I have a customer who is migrating from the internal CP to a guest page on clearpass. With the old system the captive portal page was displayed immediately a samrt device connected to the network. This isnt happening with the clearpass guest - what is the trcik to getting the client to open a web browser automatically after association.



  • 2.  RE: Internal CP to Clearpass Guest migration

    EMPLOYEE
    Posted Jul 09, 2014 08:50 AM

    What type of device is it?  Please do a search on the forum for Apple CNA or Captive Portal Network Assistant, which pops up to help the user login.

     



  • 3.  RE: Internal CP to Clearpass Guest migration

    Posted Jul 09, 2014 09:11 AM

    Sorry for the misspelling - they are smart devices and we need a web browser to open up so that they can login to Cleaarpass guest page.



  • 4.  RE: Internal CP to Clearpass Guest migration

    EMPLOYEE
    Posted Jul 09, 2014 09:16 AM

    What smart devices are they? Do they have a browser?  Please be more specific.



  • 5.  RE: Internal CP to Clearpass Guest migration

    Posted Jul 09, 2014 10:05 AM

    They are iphones and androids and yes they do have browsers.



  • 6.  RE: Internal CP to Clearpass Guest migration

    EMPLOYEE
    Posted Jul 09, 2014 10:13 AM

    To be clear, all Apple devices support this functionality, but not all Androids, do.  This is not something that you can expect of all mobile devices.  All users must be prepared to open a browser, when necessary to connect.



  • 7.  RE: Internal CP to Clearpass Guest migration

    Posted Jul 09, 2014 10:32 AM

    The same device has a different experience on the two different setups. I want to know how to force a browser to open when it connects to the SSID with the Clearpass guest portal. The customer is used to seeing this happen with the old CP and wants the same to happen with Clearpass.



  • 8.  RE: Internal CP to Clearpass Guest migration
    Best Answer

    EMPLOYEE
    Posted Jul 09, 2014 10:35 AM

    MattF,

     

    You are saying the same device, and then you are saying device(s).  Which specific device behaves differently?  Again, on the Apple side it is very well documented why this happens.  On Android, it is hit and miss based on the device.  Apples use the CNA mechanism, androids use something different and cannot be counted on for all devices...

     

    If you are witnessing the behavior with an Apple device, is is either because of the Bypass CNA functionality in the Captive Portal Authentication Profile or the same CNA functionality via a URL extension in ClearPass.  If it is with an Android device, there is no way to know what prompts it.

     

     



  • 9.  RE: Internal CP to Clearpass Guest migration

    EMPLOYEE
    Posted Jul 09, 2014 10:35 AM

    MattF,

     

    You are saying the same device, and then you are saying device(s).  Which specific device behaves differently?  Again, on the Apple side it is very well documented why this happens.  On Android, it is hit and miss based on the device.  Apples use the CNA mechanism, androids use something different and cannot be counted on for all devices...

     

    If you are witnessing the behavior with an Apple device, is is either because of the Bypass CNA functionality in the Captive Portal Authentication Profile or the same CNA functionality via a URL extension in ClearPass.  If it is with an Android device, there is no way to know what prompts it.

     

     



  • 10.  RE: Internal CP to Clearpass Guest migration

    Posted Jul 11, 2014 03:18 AM

    Have asked the customer for clarification and they have come back with a revised assessment - different scenarios with different devices. So it looks like the two captive portals are working as they should be with the clients being the deciding factor.

    Thanks for the help though.