Wireless Access

 View Only
last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

AP-Group via ClearPass

This thread has been viewed 22 times
  • 1.  AP-Group via ClearPass

    Posted Apr 13, 2021 11:39 AM
    Hi together

    I have a question regarding our Company Wifi.
    We have connect our ClearPass with the Aruba Activate. In our ClearPass we get all AP´s from the Aruba Site. This works without Problems. 
    We have also create a rule for the Access Point Authentication on our Network. This works also without Problems. 

    The next step is to assign automaticly the AP-Group via ClearPass to our Mobility Master.
    Is that possible?
    Means i will create a Rule for each Branch. If the AP get Access to the Network the AP should also get the right AP-Group.

    Is that also possible that i can give the AP the right Name in the ClearPass?

    On the end the AP is complete configured via ClearPass.

    Maybe you can help me. 
    thanks
    Andreas

    ------------------------------
    Andreas Seybold-Eptinig
    ------------------------------


  • 2.  RE: AP-Group via ClearPass

    MVP EXPERT
    Posted Apr 13, 2021 12:14 PM
    You can offload the CPSEC/RAP whitelist to ClearPass which can return the following via VSA and name/move AP to the correct group.

    ap-group: Aruba-AP-Group
    ap-name: Aruba-Location-ID
    ap-remote-ip: Aruba-AP-IP-Address

    https://www.arubanetworks.com/techdocs/ArubaOS_85_Web_Help/Content/arubaos-solutions/controlplane/mana-ap-white.htm?Highlight=external%20whitelist

    **EDIT** Someone has detailed the steps :)

    https://community.arubanetworks.com/browse/articles/blogviewer?blogkey=acd489ba-b71c-4d72-a6ae-d42294b038db

    ------------------------------
    Craig Syme
    ------------------------------



  • 3.  RE: AP-Group via ClearPass

    Posted Apr 14, 2021 04:27 AM
    Hi Craig,

    thanks for you Info.
    Thats perfect. AP Group is working now :-)

    Now i have a other Problem. The Manual describe to use a CSV-File for Access Point Import.

    We use in our Company the Aruba Activate and have configured the context Server in our ClearPass.
    I get here all Access Point via poll from Activate to our ClearPass.
    My Problem is now how can i Change the Name from the AP in the ClearPass?
    Sure i can give the Name direct via Activate to each AP but we have different Branches and this is here not Possible. 

    Is here any way to get the Data from Activate but Change the Name direct on the ClearPass?

    Thanks for your help.

    ------------------------------
    Andreas Seybold-Eptinig
    ------------------------------