Wireless Access

last person joined: 19 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Force ExpirationDate for guest-provisining profile

This thread has been viewed 0 times
  • 1.  Force ExpirationDate for guest-provisining profile

    Posted May 22, 2013 09:03 AM

    Dear All,

     

    I have installad a Guest and a Corporate WiFi networks in an Industrial Plant, the Corporate is for Internal user only (proxy and internet filters) the Guest is only for external users, this is separated from the LAN and bypass every internet controls proxy and filters.

     

    Now i must delegate the guest-provisining to no-IT people and i wish to set restrictions on the expiration time of the guest profile they will generate. I want avoid that they create eternal accounts on the Guest Network to use like a free internet account with no restriction for internal people.

     

    is it possible to force the expiration date in 2/3 days? and then disable the "End date" field?

     

    Thanks in advance.

     

     



  • 2.  RE: Force ExpirationDate for guest-provisining profile

    Posted May 22, 2013 09:16 AM

    See if this helps :

    Are you using the internal captive portal or ClearPass/Amigopod ?

    GUEST ACCOUNTs.png



  • 3.  RE: Force ExpirationDate for guest-provisining profile

    Posted May 22, 2013 10:35 AM

    Hello,

     

    Thanks for the fast reply, i'm using ArubaOS 6.1.2.3.

    From your table it seems to me that I can not costumize the guest-provisining role, it's correct? any workaround?



  • 4.  RE: Force ExpirationDate for guest-provisining profile

    Posted May 22, 2013 10:44 AM

    Guest Provisioning_2013-05-22_10-41-42.png



  • 5.  RE: Force ExpirationDate for guest-provisining profile

    Posted May 23, 2013 01:58 AM

    sorry I did not understand, I've have already used this table, but i can only enable or disable these fields ... if i disable the "end_date" then I presume the accounts created by the guest_provisiong profile are endless and this is exactly what I want to avoid.

    I want disable the "possibility of choice" of the end date and force this field in this way: end_date = start_date + 2days or something like that.

    Thanks,



  • 6.  RE: Force ExpirationDate for guest-provisining profile
    Best Answer

    Posted May 23, 2013 05:33 AM
    Sorry I should have explain when I posted the last screenshot but what I meant that is the only customization available unless you have an external guest portal clearpass/amigopod


  • 7.  RE: Force ExpirationDate for guest-provisining profile

    Posted May 23, 2013 07:45 AM

    Ok, thank you for your help!



  • 8.  RE: Force ExpirationDate for guest-provisining profile
    Best Answer

    EMPLOYEE
    Posted May 23, 2013 08:45 AM

    The command you need is this

     

    local-userdb maximum-expiration <mins>

      It will then not be possible for a guest-provisioner to create a user with a longer expiry time.  Normally done on the Master controller which is where the database is held.

     

    Hope that helps

     

    :smileyhappy:



  • 9.  RE: Force ExpirationDate for guest-provisining profile

    Posted May 23, 2013 10:39 AM

    Thank You, it works like a charm!



  • 10.  RE: Force ExpirationDate for guest-provisining profile

    Posted Jul 02, 2013 05:51 AM
      |   view attached

    Hello guys,

    I update this old post because i found a correlated problem to this issue, maybe a bug.

     

    Following the solution i'va set a maximum expiration time to 7200 mins (5 days), but when i create an user postdating the starting time, it begin to calculate the time from the creation time and not frome the starting data (please take a look to the attachment, today is 2nd july).

     

    Thanks,

    Davide

     

     

     



  • 11.  RE: Force ExpirationDate for guest-provisining profile

    EMPLOYEE
    Posted Jul 02, 2013 07:14 PM

    Please open a support case so that this can be replicated and possibly fixed.