AAA, NAC, Guest Access & BYOD

 View Only
last person joined: one year ago 

Solutions for legacy and existing products and solutions, including Clearpass, CPPM, OnBoard, OnGuard, Guest, QuickConnect, AirGroup, and Introspect

How to integrate IAP with CPPM to perform Captive Portal authentication 

Jul 18, 2014 01:58 PM

This Article explains about-

   i) adding the Aruba IAP as NAD device.
   ii) Integrating Aruba Controller with CPPM to perform Captive portal authentication.
   iii) Configuring service on CPPM to handle this request.

 

Environment : This Article is written  for CPPM 6.2.0 and greater.

 

Below are the detailed steps.

1: Adding Aruba Controller as NAD device on CPPM.

Navigate to Configuration > Network > Devices

Click Add Device

Add the device as shown below.

rtaImage.png

 

The Vendor name should be selected as Aruba and COA enabled.

also 
Make sure that we configure the same Radius Shared secret on the VC as well.

 

2: Integrate Aruba IAP  with CPPM to perform Captive Portal.

Click on "System" and fill the below details.

rtaImage (2).png

 

Give an IP to the Virtual Controller and enable Dynamic radius Proxy. This will forward all the radius packets ( from any IAP in the cluster) to CPPM with the VC's IP.

Click on " Security - >Authentication Servers " and add a new radius Server.

 

rtaImage (3).png

 

Create a new SSID.

Click on "New" and give a name to the SSID.

 

rtaImage (4).png

 

We will set the Primary Usage as Guest as this is for Guest access.

On next page, select the Client IP assignment.

We can have it either VC assigned or Network Assigned based on our requirements.

 

rtaImage (5).png

 

On the Next page,

 

rtaImage (6).png

 

Splash page type : Must be set as "External- Radius Authentication"
Auth Server : select the CPPM from the drop down.
Enable radius accounting and set accounting interval as 10 minutes.
IP or Hostname is the IP/Hostname of the CPPM server.
URL is the URL of the guest login page from the CP Guest server.

On this page, create a new Preauth role as per the details below.

 

rtaImage (7).png

 

The Preauth role must have HTTP and HTTPS access to the CPPM server. The authenticated role (it gets created by default with the SSID's name) could be customised to control access.

We can Save and Exit and this completes the configuration on the Iap.

 

3: Configuration of CPPM

Login to Clear Pass Guest and navigate to  Home » Configuration » Authentication and enble the HTTPS for Guest access as below.

Navigate to Home » Configuration » Web Logins on CPG and create a new page.

rtaImage (9).png

The name should be exactly same as the name provided in the IAP configuration.

We can leave the other configuration items as default on this page apart from inserting the Guest self registering link in the header or footer and save the page.

Click on the page and hit test to check the page look and view.

rtaImage (10).png

rtaImage (11).png

This completes the congiguration on the CP Guest.

Now, we will add a Service to handle this request.

Navigate to "
Configuration » Service Templates" use the template for  "Guest Access".

rtaImage (12).png

On the page, fill in the details as below to autofill the configuration.

rtaImage (13).png

Hit "Add Service" and the service is added.

We can then connect a client and check.

Statistics
0 Favorited
11 Views
0 Files
0 Shares
0 Downloads

Related Entries and Links

No Related Resource entered.