Security

 View Only
last person joined: 18 hours ago 

Enterprise security using ClearPass Policy Management, ClearPass Security Exchange, IntroSpect, VIA, 360 Security Exchange, Extensions and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

AOS-S Switch Named VLAN enforcement with ClearPass

This thread has been viewed 14 times
  • 1.  AOS-S Switch Named VLAN enforcement with ClearPass

    Posted 7 days ago

    I am setting up a 2930F switch for wired authentication with ClearPass.  There will be multiple locations that use different VLAN IDs at the different locations. 

    Example Location 1 MGMT VLAN ID is 100 

    Location 2 MGMT VLAN ID is 200 

    Location 3 MGMT VLAN ID is 300

    I have the enforcement currently working in our test environment if I use the standard VLAN enforcement profile to assign a VLAN based on the NAD ID.  

    Is there a way to assign an enforcement profile to use the named-vlan so we can reference the name in the enforcement profile and each switch will use that to place the user on the correct VLAN ID for that switch?

    I know I can use the DUR template but that may not be an option for this customer.

    Thanks



  • 2.  RE: AOS-S Switch Named VLAN enforcement with ClearPass

    EMPLOYEE
    Posted 7 days ago

    There is this attribute  from "Radius:Hewlett-Packard-Enterprise" that could help.

    Egress-VLAN-Name: Configures an optional, egress VLAN for either tagged or untagged packets when the VLAN ID is not known 



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: AOS-S Switch Named VLAN enforcement with ClearPass

    Posted 7 days ago

    Hi

    In your enforcement profile that sends the VLAN ID, just replace the number with the VLAN name instead.

    Edit the attribute Tunnel-Private-Group-Id and enter the name.

    The name is case sensitive, so make sure to type the name with the same case on both the switches and in the ClearPass enforcement profile.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP 2023, ACCX #1335, ACMP, ACDP, ACP-Network Security, ACEP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 4.  RE: AOS-S Switch Named VLAN enforcement with ClearPass

    Posted 6 days ago

    Hi Jonas, 

    This is great info, thanks so much I will give it a test tomorrow.

    Thanks!




  • 5.  RE: AOS-S Switch Named VLAN enforcement with ClearPass

    Posted 4 days ago

    From our testing we ended up configuring DUR enforcement profiles and using the named VLAN with the role.  Trying to use the HPE radius attribute did not seem to work as we saw the user ended up in the default VLAN.  We also tried using the named VLAN in the Private Tunnel Group ID and the user also ended up in the default VLAN.  

    DUR seems to be the way to go on this one.

    Thanks