Wireless Access

Reply
Contributor I
Posts: 50
Registered: ‎05-15-2012

Redirect to ClearPass captive portal ip issue

Hi Airheads,

 

I want to use a self register captive portal from ClearPass Guest that is in a VLAN10 in Building 1 in my test controller where i configure a SSID with a captive portal authentication that is in the VLAN192 using a ISP modem like DHCP and gateway. There's no way to communicate (to route) the VLAN10 and VLAN192 to assure security of the Data Center. Here is the topology:

 

Captive Portal.jpg

The idea is use de VLAN192 for guest, the problem is that this VLAN don't have access to the VLAN of ClearPass. It sounds logical to change the VLAN in the post authentication role but i understand that's not posibble in L3 auth.

 

I know about the ip cp-redirect-address command to solve this issue but i don't know if this command works for a ClearPass captive portal. I tried and don't work for me. Any suggestions? Thanks in advance.

Guru Elite
Posts: 8,765
Registered: ‎09-08-2010

Re: Redirect to ClearPass captive portal ip issue

You can't allow just TCP 443 into VLAN 10?


Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Contributor I
Posts: 50
Registered: ‎05-15-2012

Re: Redirect to ClearPass captive portal ip issue

Thanks capalli but the TCP 443 port is enabled.

Guru Elite
Posts: 8,765
Registered: ‎09-08-2010

Re: Redirect to ClearPass captive portal ip issue

I'm confused. So can you not currently access ClearPass from VLAN 192?


Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Contributor I
Posts: 50
Registered: ‎05-15-2012

Re: Redirect to ClearPass captive portal ip issue

No, because Captive ClearPass is in VLAN10 and the VLAN192 is for the ISP modem and the guests. For customer network security, we can not allow inter vlan routing.

MVP
Posts: 4,307
Registered: ‎07-20-2011

Re: Redirect to ClearPass captive portal ip issue

Why don't you just source nat the HTTPS/HTTP and DNS traffic directed to ClearPass using an internal address

Thank you

Victor Fabian
Lead Mobility Engineer @ Integration Partners
AMFX | ACMX | ACDX | ACCX | CWAP | CWDP | CWNA
Search Airheads
Showing results for 
Search instead for 
Did you mean: