Security

last person joined: 18 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Question about Clearpass guest and Cisco 2960 switch

This thread has been viewed 0 times
  • 1.  Question about Clearpass guest and Cisco 2960 switch

    Posted Aug 27, 2015 03:57 PM

    Hi!

     

    I am doing a lab where I have a Clearpass on vlan 13, my switch has an IP on the management vlan (12) and the guests are going to vlan 100.

     

    I wasn't able to get a proper Captive Portal redirection until I added an IP address on the Guest Vlan on my Cisco 2960.

     

    can someone enlighten me and explain the reason why the switch needs an IP address on the guest Vlan to get the clients redirected to clearpass captive portal?

     

    the guest gateway is my firewall.

     

    thank you!!



  • 2.  RE: Question about Clearpass guest and Cisco 2960 switch

    EMPLOYEE
    Posted Aug 27, 2015 03:58 PM
    The VLAN must have an IP address so that traffic can be routed to VLAN 13
    where ClearPass lives. Otherwise, it's just a private VLAN where traffic
    can't exit.


  • 3.  RE: Question about Clearpass guest and Cisco 2960 switch

    Posted Aug 27, 2015 04:02 PM

    Still confused.

     

    the guests have their gateway on the upstream firewall.

     

    the process of http redirection is not very clear to me.

     

    I understand that the switch captures the request and sends a 301 code saying "your webpage changed! Please go to clearpass"...

     

    but why can't this work without the IP address on the guest Vlan? :)

     

    thank you



  • 4.  RE: Question about Clearpass guest and Cisco 2960 switch

    EMPLOYEE
    Posted Aug 27, 2015 04:07 PM
    Because the client needs IP connectivity to ClearPass.


  • 5.  RE: Question about Clearpass guest and Cisco 2960 switch

    Posted Aug 28, 2015 04:15 AM

    Hi!

     

    The Guest Gateway has routes to CPPM so in terms of pure routing everything is "prepared" to let the guest clients to reach CPPM



  • 6.  RE: Question about Clearpass guest and Cisco 2960 switch

    Posted Aug 28, 2015 11:34 PM

    In my environment we put the guest VLANs on the controller and the Corp VLANs on the Cisco.  From the Cisco we trunk the corp VLANs and the management VLAN to the controller and route the guest VLAN to the controller.  On the controller we have a default route on the controller pointing to the switch.  No need to have any guest vlans on the switch but as others have said you still have to route.