Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

VLAN derivation on split tunnel RAP

This thread has been viewed 3 times
  • 1.  VLAN derivation on split tunnel RAP

    Posted Apr 27, 2015 10:24 AM

    We're currently in the process of consolidating our SSIDs into one.  This has been achieved for the vast majority of locations where CAPs are employed in bridge mode, using ClearPass to return user role and VLAN attributes.

     

    However, the VLAN derivation via the VSA returned by ClearPass does not work where RAPs have been employed in split tunnel mode.  Although the user role is updated correctly, clients stay on the initial VLAN.  I've tried assigning the VLAN to the user role too, but the VLAN still doesn't change.

     

    I have read that split tunnel RAPs do not support VLAN derivation - can anyone confirm this?



  • 2.  RE: VLAN derivation on split tunnel RAP
    Best Answer

    EMPLOYEE
    Posted Apr 27, 2015 10:45 AM
    Correct. Split tunnel raps do not support Vlan derivation.


  • 3.  RE: VLAN derivation on split tunnel RAP

    Posted Apr 27, 2015 10:46 AM

    Thanks for the reply.

     

    Is there any other way to change the initial VLAN assignment in this example?



  • 4.  RE: VLAN derivation on split tunnel RAP

    EMPLOYEE
    Posted Apr 27, 2015 10:53 AM
    Unfortunately, there is not. Split tunnel only makes sense when the location does not have a dedicated wan connection back to your location besides the ipsec tunnel. If it does have a connection, it is more efficient to use bridge mode. Of the locations where there is no other connection, it is assumed there is probably only one Vlan.

    What is your setup?


  • 5.  RE: VLAN derivation on split tunnel RAP

    Posted Apr 27, 2015 11:12 AM

    These are for locations where there is no dedicated link or VPN tunnel, i.e. home users. Two VLANs have been configured on the controller; one for corporate devices and one for BYOD devices.  The VLAN assigned is based on logic present in ClearPass.  The default initial VLAN assigned is the BYOD VLAN.  The problem is that we cannot assign the other VLAN if the client is detected to be a corporate device.



  • 6.  RE: VLAN derivation on split tunnel RAP

    EMPLOYEE
    Posted Apr 27, 2015 12:23 PM
    Got it. That is a very unique use case where a byod device is allowed remotely. Does the byod devices require any resources from the headend, or basically all internet?


  • 7.  RE: VLAN derivation on split tunnel RAP

    Posted Apr 27, 2015 12:33 PM

    Some internal resources, mainly http(s) based, but not entirely.