Security

 View Only
last person joined: 7 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).

Cisco Mobility Express AP's with ClearPass Guest

This thread has been viewed 5 times
  • 1.  Cisco Mobility Express AP's with ClearPass Guest

    Posted Feb 24, 2021 03:46 AM

    Hi All,

    Has anyone configured Cisco ME with ClearPass Guest? I have it configured and working but not working 100%

    Cisco ME version 8.10.142 (latest version)
    ClearPass 6.9.0

    On the ME
    Guest SSID created
    Mac filtering and mac failure options enabled
    radius auth selected as other
    selected the radius server (cppm) and for accounting
    page for guest registration details entered.

    i had to enable mac filtering and failure option otherwise i dont even see the request come into clearpass access tracker.

    CPPM
    the guest mac auth service only has an allow enforcement profile (in access tracker it still shows in "red" rejected but has the allow profile is returned.
    then the page is displayed and all works as expected with sponsor confirmation.

    Guest with mac caching service - post auth acl is returned with internet access only when the user connects with the created/approved account.

    Issue is when you want to connect the next day or with a device that has already connected to the corporate ssid- the redirect doesnt seem to happen and i can see the mac auth failes and it should then work as stated in previous steps. when i look at the cisco wlc me i dont even see the client connected to the guest ssid...once i clear the cache for the guest user and device source and try again then it works.

    Any ideas, looking for someone that has this configured on mobility express specifically 




    ------------------------------
    Pieter Le Roux
    ------------------------------