Wired Intelligent Edge

last person joined: yesterday 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

Wired Captive Portal and Cisco switches

This thread has been viewed 7 times
  • 1.  Wired Captive Portal and Cisco switches

    Posted Jul 31, 2013 04:58 PM

    Is it posible to configure wired captive portal on Aruba controller and Cisco switches? Controller is connected via trunk port-channel to cisco switch. When computer is connected to switch on port where is configured untrusted vlan it should get captive portal. Computer gets IP address from DHCP server and it has default gateway set to router. How to tunnel traffic from Cisco switch to controler on that specyfic vlan. I know there is tunnel-node on Aruba switches but how to do it on cisco?

     

    wired.jpg



  • 2.  RE: Wired Captive Portal and Cisco switches

    EMPLOYEE
    Posted Jul 31, 2013 09:24 PM

    You can do this but you need to just trunk the VLAN to the edge port on the Cisco and terminate that VLAN on the controller in an untrusted configuration.

     

    The tunnel configuration you are asking about is for Aruba switches only...I recommend this route! :)



  • 3.  RE: Wired Captive Portal and Cisco switches

    EMPLOYEE
    Posted Jul 31, 2013 09:26 PM

    You could also use ClearPass "natively" with your Cisco switches for web auth/captive portal.



  • 4.  RE: Wired Captive Portal and Cisco switches

    Posted Aug 01, 2013 12:17 AM

    Read this for a quick summary:  https://arubanetworkskb.secure.force.com/pkb/articles/HowTo/R-1183.

     

    In order for this to work, the controller needs to see this traffic.  You mention that your default gateway is the router; try changing that to the controller so the traffic is forced through the untrusted port.



  • 5.  RE: Wired Captive Portal and Cisco switches

    Posted Aug 01, 2013 12:50 AM
    Default gateway on controller is preferred, but alternative is throwing the vlan on the Cisco switch into a GRE tunnel between switch and controller. Traffic them flows client > switch > tunnel > controller > router.


  • 6.  RE: Wired Captive Portal and Cisco switches

    Posted Aug 01, 2013 06:21 PM

    Funny, my boss came in this mornign and requested I figure this out for our environment.

     

    My Cisco tunnel isn't making sense to me. (My Cisco tunnel-fu is very weak)

     

    Anyone have a code-snippet to share?



  • 7.  RE: Wired Captive Portal and Cisco switches

    Posted Aug 01, 2013 02:23 PM

    Thank you all for reply.

    I don't want to change default gateway to controller so better for me will be GRE tunnels. How to configure it? I know how to untrust vlan and assign wired profile to it but I don't have clue how to make GRE tunnels between cisco and aruba and send only one vlan. Is there same kind of manual or can someone please write me some config?