Regular Contributor II

VLAN assignment with clearpass

Dear all, 


I am new in CPPM, so please help me on this.


i have a Aruba controller, & a CPPM, 


Now i want to create users in cppm's internal DB, and assign them to different vlan but using

one SSID.


Means  one SSID is there  [ CORP ], and if sales person connect to it, the he/she will get a vlan. And if technical person connect to it then he/ she will get different vlan.


how can i do this ?


kindly tell me what things will be required..



Re: VLAN assignment with clearpass


First create the roles you need , Sales , IT , etc..

2015-01-16 06_23_47-ClearPass Policy Manager - Aruba Networks.png


Then add the new users to the local db and assign the roles to each user

2015-01-16 06_24_28-ClearPass Policy Manager - Aruba Networks.png


Then create an enforcement profile with the VLANs you are planning to send to the controller based on the TIPS ROLE condition wheter is Sales or IT


2015-01-16 06_25_49-ClearPass Policy Manager - Aruba Networks.png


And finally in your policy use the TIPS ROLE condition to send the VLAN assignment

2015-01-16 06_26_41-ClearPass Policy Manager - Aruba Networks.png

Thank you

Victor Fabian
Lead Mobility Engineer @ Integration Partners
Regular Contributor II

Re: VLAN assignment with clearpass

Thank you victor....


Now i understand,  and also its working.


thank you again, you are a great man.

New Contributor

Re: VLAN assignment with clearpass

Hi, same problem but a little diference. I have around 2500 users and I would need 1000 of them with a different vlan EACH one (on a big congress center, for shaping, monitoring etc). It's this solution escalable to 1000_1500 different roles_vlans? (No matter how mu h time it cost to configure) It's there a better way?

Guru Elite

Re: VLAN assignment with clearpass

What is the identity store you're using?

Tim Cappalli | Aruba Security TME
@timcappalli | | ACMX #367 / ACCX #480
Guru Elite

Re: VLAN assignment with clearpass

Why would you put 2500 users into 1000 different VLANS?

Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

New Contributor

Re: VLAN assignment with clearpass

Hi, I haven't it configured. I'm preparing a clearpass pilot for big venue center at barcelona and I know this is an historic request that they solve by dot1x. That causes tons of complaints with windows users. We solve it with aruba quick connect for autoconfig pcs but not very efficient (users need wifi to reach the url).
New Contributor

Re: VLAN assignment with clearpass

Well do t think on the tipycall guest/corporative architechture, we act sometimes as a "little service provider". There is a lot of reasons, to isolate users, have different n3 an n2 configs, monitor separated traffic. Sometimes we have high technologicall venues (1000 and up exhibitors) and we have to configure in very very short time (hours) so many different and sometimes complex lans and had the hability to change, troubleshoot. No other way than vlans I guess to do that.
Search Airheads
Showing results for 
Search instead for 
Did you mean: