Hi everyone,
We're extremely new to setting up Aruba wireless networks and I'm trying to figure out exactly the process I should be using for our secure wireless network. We have both Airwave and Clearpass running, but I don't think they're talking to each other correctly, and I've been tasked with seeing if I can make this work.
Currently, we have all of our Aruba devices showing up in Airwave, and Airwave is managing all of them and the Instant Virtual Controller at each of our physical sites. This works great, and we're able to push AP configurations out with Instant Config in Airwave. We're also authenticating to Airwave itself for management via LDAP/RADIUS authentication, and authenticating clients on an SSID using LDAP/RADIUS as well. Pretty basic so far.
What I'm struggling with is the correct way to integrate Clearpass. I originally was looking at this link, but I'm now thinking that all this is doing is telling Airwave "hey, ClearPass is up and running too, as well as your AP's". That doesn't add Clearpass as an authentication method.
Next, I tried looking here and here as ways of getting Airwave to authenticate through ClearPass, and those seem to point me a bit more in the right direction. But if I understand them correctly, I'd end up just authenticating Airwave with a local user database in ClearPass, which also isn't what I want.
So, am I correct in thinking that to accomplish fine tuned authentication to an SSID which would allow an authenticated user with a company owned device to access our internal network, I'd have to have ClearPass authenticating to our LDAP/RADIUS server, and Airwave authenticating via RADIUS to ClearPass?
Would this give me the ability to:
•Configure "Authentication server" 1 or 2 in Instant Config > Security as "ClearPass"?
•Log into Airwave using our LDAP credentials for authorized users (or would Airwave also need to authenticate to our LDAP/RADIUS server directly, as it's currently set up to do?)?
Thanks very much in advance for any information anyone can provide to lead me in the right direction.