Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

AOS-S Switch Named VLAN enforcement with ClearPass

This thread has been viewed 17 times
  • 1.  AOS-S Switch Named VLAN enforcement with ClearPass

    Posted Mar 14, 2023 02:03 PM

    I am setting up a 2930F switch for wired authentication with ClearPass.  There will be multiple locations that use different VLAN IDs at the different locations. 

    Example Location 1 MGMT VLAN ID is 100 

    Location 2 MGMT VLAN ID is 200 

    Location 3 MGMT VLAN ID is 300

    I have the enforcement currently working in our test environment if I use the standard VLAN enforcement profile to assign a VLAN based on the NAD ID.  

    Is there a way to assign an enforcement profile to use the named-vlan so we can reference the name in the enforcement profile and each switch will use that to place the user on the correct VLAN ID for that switch?

    I know I can use the DUR template but that may not be an option for this customer.

    Thanks



  • 2.  RE: AOS-S Switch Named VLAN enforcement with ClearPass

    EMPLOYEE
    Posted Mar 14, 2023 04:53 PM

    There is this attribute  from "Radius:Hewlett-Packard-Enterprise" that could help.

    Egress-VLAN-Name: Configures an optional, egress VLAN for either tagged or untagged packets when the VLAN ID is not known 



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: AOS-S Switch Named VLAN enforcement with ClearPass

    Posted Mar 14, 2023 04:54 PM

    Hi

    In your enforcement profile that sends the VLAN ID, just replace the number with the VLAN name instead.

    Edit the attribute Tunnel-Private-Group-Id and enter the name.

    The name is case sensitive, so make sure to type the name with the same case on both the switches and in the ClearPass enforcement profile.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP 2023, ACCX #1335, ACMP, ACDP, ACP-Network Security, ACEP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 4.  RE: AOS-S Switch Named VLAN enforcement with ClearPass

    Posted Mar 16, 2023 01:33 AM

    Hi Jonas, 

    This is great info, thanks so much I will give it a test tomorrow.

    Thanks!




  • 5.  RE: AOS-S Switch Named VLAN enforcement with ClearPass

    Posted Mar 17, 2023 04:36 PM

    From our testing we ended up configuring DUR enforcement profiles and using the named VLAN with the role.  Trying to use the HPE radius attribute did not seem to work as we saw the user ended up in the default VLAN.  We also tried using the named VLAN in the Private Tunnel Group ID and the user also ended up in the default VLAN.  

    DUR seems to be the way to go on this one.

    Thanks