Security

 View Only
last person joined: 19 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass role without mobility controller/IAP

This thread has been viewed 25 times
  • 1.  Clearpass role without mobility controller/IAP

    Posted Feb 08, 2021 12:27 PM
    Hi,


    My environment  is instant-on using Radius authentication with clearpass integrated with AD.

    It's working now by log-in SSID with AD user.

    Now,I understand how role,role mapping work with Clearpass and mobility controller/IAP.So, The controller can be assign another VLAN where role mapped.

    My question is How can I assign vlan mapping without mobility controller/IAP on my network?

    Anything I can do with my instant-on and clearpass without mobility controller/IAP?

    ------------------------------
    purinut chuparn
    ------------------------------


  • 2.  RE: Clearpass role without mobility controller/IAP

    MVP GURU
    Posted Feb 08, 2021 03:38 PM

    Hi,

    What firmware release do you have on the IAP ?

    There is parameter to enable Download User Role on IAP or you can send directly a user role with clearpass via VSA



    ------------------------------
    PowerArubaSW : Powershell Module to use Aruba Switch API for Vlan, VlanPorts, LACP, LLDP...

    PowerArubaCP: Powershell Module to use ClearPass API (create NAD, Guest...)

    PowerArubaCX: Powershell Module to use ArubaCX API (get interface/vlan/ports info)..

    ACEP / ACMX #107 / ACDX #1281
    ------------------------------



  • 3.  RE: Clearpass role without mobility controller/IAP

    Posted Feb 09, 2021 09:02 PM
    Hi alagoutte,

    Thanks for your answer. But As I mentioned I do not have any IAP/MC. I do have only Aruba Instant On.

    ------------------------------
    purinut chuparn
    ------------------------------



  • 4.  RE: Clearpass role without mobility controller/IAP

    MVP GURU
    Posted Feb 10, 2021 02:47 PM
    for me, it is not possible

    ------------------------------
    PowerArubaSW : Powershell Module to use Aruba Switch API for Vlan, VlanPorts, LACP, LLDP...

    PowerArubaCP: Powershell Module to use ClearPass API (create NAD, Guest...)

    PowerArubaCX: Powershell Module to use ArubaCX API (get interface/vlan/ports info)..

    ACEP / ACMX #107 / ACDX #1281
    ------------------------------



  • 5.  RE: Clearpass role without mobility controller/IAP

    Posted Feb 11, 2021 07:40 PM
    Instant On is an SMB product and is not designed to be used with an enterprise policy engine like ClearPass Policy Manager. 

    You can try using a generic VLAN enforcement profile, but no guarantee it will work.

    ------------------------------
    Tim C
    ------------------------------