Hi.
I am implementing a ClearPass Onboard in a Hospital who owns Aruba 205 IAPs and HPE 460 APs. ClearPass Onboard is working fine with Aruba Instant APs but I am having problems with the HPE side. They have an HPE Unified Wireless Controllers and about 200 APs. The problem is happening during the onboarding process of android devices.
I setup some portal free rules to allow users connected to the onboard SSID to download de QuickConnec from Play Google Play store. I have tried the usual rules showed below but its not working.
portal user-url *.ggpht.com free
portal user-url android.clients.google.com free
portal user-url *.play.googleapis.com free
portal user-url www.googleapis.com free
portal user-url *.gvt1.com
portal free-rule 10 source ip any destination ip 192.1.0.40 mask 255.255.255.255
portal free-rule 11 source ip any destination ip 192.131.0.0 mask 255.255.255.0
portal free-rule 12 source ip any destination ip 192.2.1.0 mask 255.255.255.0
portal free-rule 13 source ip 192.131.0.0 mask 255.255.255.0 destination ip 172.217.0.0 mask 255.255.0.0
where:
192.1.0.40 is customer's DNS address
192.2.1.0 is the subnet from CPPM Subnet
192.131.0.0 /24 is Onboarding Subnet
172.217.0.0 /16 is one of the google domain subnets
I have associated these rules to my Interface Vlan 131
interface Vlan-interface131
description Onboard
ip address 192.131.0.10 255.255.255.0
portal server CPPM2 method direct
portal domain cppm
portal url-param include user-url
I have also tried the
After connecting to the Onboarding SSID it opens the Onboard Portal and after authenticating with AD credenciasl it prompts for the QuickConnect installs but can't download it.
Just to confirm that problem was caused by Unified fireeall I added a portal rule allowing subnet 192.131.0.0 /24 to any and QuickConnect was download without any problem
Does anyone have a sucessfull implemention of ClearPass Onboard with HPE Unified controllers that can be shared with me ?
I am not having problems onboarding Windows devices.
I am attching a screenshow showing where the downloading process stops.
It is missing some google playstore to be allowed on the Controller.
Any ideas ?
Thanks.
Luis Rodrigues
(HPE/Aruba Partner Sâo Paulo Brazil)