Wireless Access

last person joined: 10 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Redirect to Guest SSID upon Auth failure

This thread has been viewed 2 times
  • 1.  Redirect to Guest SSID upon Auth failure

    Posted Dec 22, 2015 01:49 AM

    Hi All

     

    Was wondering if it will be possible to redirect a client to a different SSID on a normal Aruba Controller setup without using a Clearpass?

    I want to look at achieving something similar to when a controller blacklists a client upon Auth failure, but instead of blacklisting them, I want them redirected to my Guest SSID.

    Is this possible without a clearpass or similar UAC?



  • 2.  RE: Redirect to Guest SSID upon Auth failure
    Best Answer

    Posted Dec 22, 2015 02:17 AM

    No, you can't trigger their devices to connect to a different SSID (even if you did have Clearpass) in this scenario. A reject from the Radius here will prevent the device from associating with the .1x SSIDso you can't place it in a captive portal role either.

     

    That said - it is possible that the device itself might choose to connect to another SSID if it fails to connect to preferred one. That in turn require that the device has already been connected to the SSID before and wants to do it again "when all else fails"... Not something I would do tho - as a common routine for your users seems to be a better solution..

     



  • 3.  RE: Redirect to Guest SSID upon Auth failure

    Posted Dec 22, 2015 03:54 AM

    Hmm - ok - So no SSID redirect..

     

    Would it then be feasible or possible to drop a user who failed Authentication into a different Vlan on the same SSID? But then the assosciation reject from Radius wil still be an issue then I guess.

     

    So in short - if Auth Fails you can't move the client to different role, vlan or anything of the likes?



  • 4.  RE: Redirect to Guest SSID upon Auth failure
    Best Answer

    EMPLOYEE
    Posted Dec 22, 2015 07:39 AM
    Unfortunately you can't fail open with 802.1X. If authentication fails, that's the end of the road.

    Sent from Nine