Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Onboarding device enrollment from a secure SSID

This thread has been viewed 1 times
  • 1.  Onboarding device enrollment from a secure SSID

    Posted Dec 15, 2016 02:47 PM

    Hi Forum,

    2 SSID's TLS and open. What would be the best way to enroll (register) a BYOD device from the secure SSID so I can connect it to the open SSID and get the onboarding workflow.

    So employee on the TLS connected device can enroll 1 device on the open SSID. I hope I'm making sense.

     

    Thanks,



  • 2.  RE: Onboarding device enrollment from a secure SSID

    EMPLOYEE
    Posted Dec 15, 2016 02:50 PM

    I'm not sure I'm following. 

     

    A standard dual SSID onboard would have a link at the bottom of the open captive portal with a link to the Onboard enrollment workflow.



  • 3.  RE: Onboarding device enrollment from a secure SSID

    Posted Dec 15, 2016 02:54 PM

    With dual, employee would have to provide AD credentials on the captive portal. I want to do this without AD but for devices that are pre registered.



  • 4.  RE: Onboarding device enrollment from a secure SSID
    Best Answer

    EMPLOYEE
    Posted Dec 15, 2016 02:56 PM
    The Onboard workflow will always require some type of authentication whether
    it be a ClearPass web login, SAML/SSO, or OAuth2.


  • 5.  RE: Onboarding device enrollment from a secure SSID

    Posted Dec 15, 2016 02:57 PM

    Thank you for the clarification.



  • 6.  RE: Onboarding device enrollment from a secure SSID

    Posted Dec 19, 2016 03:25 AM

    On that note Tim.. On a single SSID solution - how to get single sign-on working for the onboarding workflow using the authentication session from the .1x?



  • 7.  RE: Onboarding device enrollment from a secure SSID

    EMPLOYEE
    Posted Dec 19, 2016 06:19 AM
    You can use Aruba Auto Sign-On with the caveat that you won't be able to do manual enrollment.