Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Clearpass RAP offboarding re-authentication interval?

This thread has been viewed 1 times
  • 1.  Clearpass RAP offboarding re-authentication interval?

    Posted Feb 18, 2017 12:47 PM

    I've found a few very good tutorials on setting up offloading the RAP whitelist to Clearpass for onboarding new RAPs, but one thing that's not clear to me is if that's a one-shot, first time deal, or are the RAPs reauthenticated periodically?  Basically, I'm looking to start deploying some RAPs to end users in the nearish future, and have an eye on what the offboarding process will look like.  If I could can an entry in Clearpass and have it also get deauthenticated from the controllers, that would be a big win.  (Bonus points if I could associate an AD account with each RAP, and have it's whitelist entry withdrawn when the AD account gets terminated!)



  • 2.  RE: Clearpass RAP offboarding re-authentication interval?

    EMPLOYEE
    Posted Feb 18, 2017 12:49 PM
    The RAP is authenticated when it attempts to connect to the controller. It
    would only reauthenticate if it rebooted and reconnected.



    All APs operate the same way. Campus APs are validated against the internal
    whitelist when they first connect.


  • 3.  RE: Clearpass RAP offboarding re-authentication interval?

    Posted Feb 18, 2017 12:53 PM

    OK, so that just means that we'd need to include disabling any issued RAPs as part of our manual offboarding process.  Not as ideal as just doing Clearpass magic, but good to know nonetheless.

     

    thanks!



  • 4.  RE: Clearpass RAP offboarding re-authentication interval?

    EMPLOYEE
    Posted Feb 18, 2017 12:49 PM
    The RAP is authenticated when it attempts to connect to the controller. It
    would only reauthenticate if it rebooted and reconnected.



    All APs operate the same way. Campus APs are validated against the internal
    whitelist when they first connect.