Controllerless Networks

last person joined: 2 days ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

IAP Role based access changes to Network Based

This thread has been viewed 3 times
  • 1.  IAP Role based access changes to Network Based

    Posted Mar 08, 2013 06:56 AM

    Instant version 6.2.0.0-3.2.0.2_37229 on IAP105

     

    When I set the access type on an SSID to role based it's not saved as role based. It save the access settings as network based using the rules assigned in the role I configured.


    I'll explain in images.


    Here I set the access as role based, and clicked finish.

     

    ccp access.JPG

     

    The access type dioesn't update...

     

    ccp info.JPG

     

    Checking the access type when editing the SSID shows it as network based using the setting I configured in the role CCP.

    ccp access 2.JPG

     

    I've tried this on different SSIDs with different security types and I'm getting the same results. 

     

    Anyone else getting this before I reset my instants and reconfigure?

     

    Cheers

    James



  • 2.  RE: IAP Role based access changes to Network Based

    Posted Mar 08, 2013 02:36 PM

    not 100% sure, but i think i encountered the same thinking back about it. is it an issue for you? in principe it doesn't matter much if you don't change rules via clearpass or such.



  • 3.  RE: IAP Role based access changes to Network Based

    Posted Mar 08, 2013 05:52 PM

    Yeah, it's a bit of a pain to be honest. 

     

    I configured an SSID and assigned it to be role based access then attempted to edit the role from with the PEF menu. Obviously this didn't work as it was set to network based...

     

    TAC suspect that it's a browser issue and that does make sense. I'll test it next week and report back.

     

    James



  • 4.  RE: IAP Role based access changes to Network Based

    Posted Mar 10, 2013 02:28 PM

    i tried this to confirm and the same happens for me (6.2 / 3.2 _ 37229), but i can edit the role fine in PEF > Roles menu, it even udates the situation then in network-based access at the network. in principe it is the same if you don't use the extra features in the role-based menu.



  • 5.  RE: IAP Role based access changes to Network Based

    Posted Mar 11, 2013 09:21 AM

    That's interesting. What browser are you using? I only tested this on Chome Version 25.0.1364.152 m.



  • 6.  RE: IAP Role based access changes to Network Based

    Posted Mar 11, 2013 03:07 PM

    firefox, can't lookup the exact version right now, but probably one of the latest ones.



  • 7.  RE: IAP Role based access changes to Network Based
    Best Answer

    Posted Mar 14, 2013 12:45 PM

    OK, apparently this is by design.

     

    From TAC:

    Role based with adding access list in role:

     

    • When we configure a SSID with role based normally (i.e) with the acl “allow any to all destinations” then after saving the configuration it will change it to network based.
    • This is because we are just adding the ACL in the role and this will get applied to all the users who are connecting to that SSID
    • This is an expected behavior

    --------------------------

     

    This doesn't really make sense to me. If I assign an SSID to be role based I expect to be able to modify that role to change the access that users get when connected to that SSID.

     

    I've put this forward as a "feature request".

     

    Cheers

    James



  • 8.  RE: IAP Role based access changes to Network Based

    Posted Mar 14, 2013 03:07 PM
    thanks for the update, good to know.

    @jrwhitehead wrote:

    If I assign an SSID to be role based I expect to be able to modify that role to change the access that users get when connected to that SSID.


    i still don't fully get your remark here, you can change the role, well you can change the firewall rules and then those are applied on the network based settings.



  • 9.  RE: IAP Role based access changes to Network Based

    Posted Mar 15, 2013 05:08 AM

    Gotcha. So, it is doing what it's supposed to but just not setting it as role based.



  • 10.  RE: IAP Role based access changes to Network Based

    Posted Mar 15, 2013 03:18 PM

    i guess so and as long as you don't use a pre auth role or machine auth there is nothing wrong with that. the only thing i wonder is if you can send a role with the radius reponse now and if that gets picked up correctly.



  • 11.  RE: IAP Role based access changes to Network Based

    EMPLOYEE
    Posted Mar 17, 2013 01:33 PM

     

    There are Product Enhancements filed to change this confusing behavior.

     

    I'd like to hear from the community  if our expectations are correct - once any "Role based" entry is created - any return to this screen should depict the previously configured "role based", and not revert to showing the "network based", without having to add extra configuration parameters.

     

    Thoughts ?

     

     

     



  • 12.  RE: IAP Role based access changes to Network Based

    Posted Mar 19, 2013 05:45 AM

    i would go a step further, once i have selected the role-based settings with the slider, even without changing anything or creating any extra role i expect it to remain selected to role-based.