Security

last person joined: 10 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Single SSID Onboarding for Controllers Guide

This thread has been viewed 8 times
  • 1.  Single SSID Onboarding for Controllers Guide

    Posted Nov 07, 2016 11:33 AM

    Hey guys, I am looking for the latest step by step guide to setup clearpass onboarding for controllers using a single SSID. 

     

    Thanks!



  • 2.  RE: Single SSID Onboarding for Controllers Guide

    EMPLOYEE
    Posted Nov 07, 2016 11:36 AM

    There is no specific guide for this. Have you reached out to your Aruba partner?



  • 3.  RE: Single SSID Onboarding for Controllers Guide

    Posted Nov 07, 2016 11:38 AM

    Thanks, I am actually the Aruba partner and I'm Clearpass certified, I haven't setup single SSID onboard in a long time and was hoping Aruba had some decent documentation around a generic setup. 



  • 4.  RE: Single SSID Onboarding for Controllers Guide

    EMPLOYEE
    Posted Nov 07, 2016 11:50 AM

    Essentially the only configuration that makes it a single SSID Onboard is adding an enforcement rule that checks if the outer method is EAP-PEAP, and if so, put the device into an Onboard enrollment role. You can layer on policy checks for more advanced policies.

     

    Keep in mind that all of the security issues around PEAPv0/EAP-MSCHAPv2 still apply with single SSID Onboard during the initial authentication. If your customer is security conscious, I'd recommend dual SSID Onboard.



  • 5.  RE: Single SSID Onboarding for Controllers Guide
    Best Answer

    Posted Nov 07, 2016 01:28 PM

    Check out the following ASE solution,

    Wireless Onboard w/ Single SSID 

    https://ase.arubanetworks.com/solutions/id/34

     



  • 6.  RE: Single SSID Onboarding for Controllers Guide

    Posted Nov 15, 2016 10:14 AM

    Following this ASE, I was able to get single SSID onboarding working as designed. Thanks!