Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Role Mapping - Smart Devices

This thread has been viewed 3 times
  • 1.  Role Mapping - Smart Devices

    Posted Jul 29, 2014 04:03 PM

    Within CPPM, is there a way to define a role mapping for all smartdevices (Andriod, iOS, Blackberry)? I try the following an it's not working.

     

    SmartDevice Role Mapping.PNG



  • 2.  RE: Role Mapping - Smart Devices

    EMPLOYEE
    Posted Jul 29, 2014 04:05 PM
    Authorization:[Endpoints Repository] Category EQUAL Smartdevice


  • 3.  RE: Role Mapping - Smart Devices

    Posted Jul 29, 2014 04:12 PM

    I can only set it like this and it still not working..

     

    SmartDevice Role Mapping_v2.PNG



  • 4.  RE: Role Mapping - Smart Devices

    Posted Jul 29, 2014 04:16 PM

    OK...i got the setting per your suggesting and it's till not working...

     

    SmartDevice Role Mapping_v3.PNG



  • 5.  RE: Role Mapping - Smart Devices

    EMPLOYEE
    Posted Jul 29, 2014 04:30 PM

    If you lookup the device in the endpoint repository, is it profiled?



  • 6.  RE: Role Mapping - Smart Devices

    Posted Jul 29, 2014 04:37 PM

    Profile is "No".



  • 7.  RE: Role Mapping - Smart Devices

    EMPLOYEE
    Posted Jul 29, 2014 04:39 PM
    Do you have DHCP relays configured pointing to ClearPass?


  • 8.  RE: Role Mapping - Smart Devices

    Posted Jul 29, 2014 04:43 PM

    No. Not sure where to do that at. Our DHCP are handle by the domain controller.



  • 9.  RE: Role Mapping - Smart Devices

    EMPLOYEE
    Posted Jul 29, 2014 04:46 PM
    Wherever your layer 3 interfaces live for the clients, you need to add DHCP relays pointing to the ClearPass servers.


  • 10.  RE: Role Mapping - Smart Devices

    Posted Jul 29, 2014 04:49 PM

    We have the DHCP relay point to our DHCP server currently. If I were to change that to Clearpass would that break DHCP to my Domain controller who is handling out the IP? How is that suppose to fix DeviceFinger printing of SmartDevices?



  • 11.  RE: Role Mapping - Smart Devices

    EMPLOYEE
    Posted Jul 29, 2014 04:51 PM
    You would add the relay in addition to the one pointing to your DHCP server. It will not break DHCP. You need this for profiling. There are other ways but they are not as "instant".


  • 12.  RE: Role Mapping - Smart Devices

    Posted Jul 29, 2014 06:45 PM

    Under "Services", do i need to check "Profile Endpoints"?

     

    SmartDevice Role Mapping_v4.PNG



  • 13.  RE: Role Mapping - Smart Devices

    EMPLOYEE
    Posted Jul 29, 2014 06:47 PM

    You can, yes, but you still need to add DHCP relays.



  • 14.  RE: Role Mapping - Smart Devices

    Posted Jul 29, 2014 06:55 PM

    Yes. I have already added an additional DHCP relay under my switch/router SVI to point to CPPM. Still no dice.

     

    The "enable profiler is enable.

    SmartDevice Role Mapping_v6.PNG

     

     

    Also, I am seeing device being profile:

     

     

    SmartDevice Role Mapping_v5.PNG

     

     

    Just not sure why my role mapping is not working:

     

    SmartDevice Role Mapping_v7.PNG

     

     



  • 15.  RE: Role Mapping - Smart Devices

    Posted Aug 22, 2014 05:43 AM

    because the Category is embedded and not smart device. try with something like an iPhone or Galaxy phone.