Security

Reply
Occasional Contributor II

clearpass cluster

Dear Community,

 

I'm facing an issue. One of our customer would like to buy a CP-VA-5K with OnBoard modul as well. They already have a CP-VA-500. We'd like to combine the two appliance to a cluster, in order to have 5500 CPPM licence. For a firewall prospective they want to know: will the two appliance has one (cluster) IP?

I know in HA mode there is a virtual IP, but in this case there is no HA, only a regular cluster with a publisher and a subscriber node.

Thank you for your help in advance!

 

Aruba

Re: clearpass cluster

The virtual ip is only failover it does not load balance
Thank You,
Troy

--Give Kudos: found something helpful, important, or cool? Click Kudos Star in a post.

--Problem Solved? Click "Accepted Solution" in a post.
Occasional Contributor II

Re: clearpass cluster

Hi Troy,

 

Thank you for your quick answer. One thing is not clear. If we want to use the guest module and a captive portal provided by ClearPass, which IP do I have to use, when I configure the captive portal's url on the controller.

 

Aruba

Re: clearpass cluster

This is more of a design question that you should work with your Aruba SE to see what works best for your network.

There are multiple options. The most common is that the URL is pointed to the VIP for captive portal and then they point the radius directly to the pub or sub.
Thank You,
Troy

--Give Kudos: found something helpful, important, or cool? Click Kudos Star in a post.

--Problem Solved? Click "Accepted Solution" in a post.
Moderator

Re: clearpass cluster

Take a look at my  CPPM Clustering TechNote 


Best Regards
-d

ClearPass Product Manager

-- Found something helpful, important, or cool? Click the Kudos Star in a post.
-- Problem Solved? Click "Accept as Solution" in a post.
Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: