Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Acceptable Use Policy and PEAP

This thread has been viewed 1 times
  • 1.  Acceptable Use Policy and PEAP

    Posted Aug 08, 2017 10:01 AM

    Hi

     

    I have a request for users to accept a "Acceptable Use Policy".

     

    all userses log in with PEAP, users are students and administrative users on the samme ssid, and is then placed in a vlan pased on role in AD. 

    Users log in and sould then be presented wtth the page and if accpted then given full access. The page is only shown 1 time eatch semester.

     

    This also gives posibility to give non human devices access with no page,

    based on the endpoint database.

     

    Is there any way to redirect after sucessfull login with PEAP.

     

    Thanks for helping out.

     

    Erik Loeth 

    Denmark



  • 2.  RE: Acceptable Use Policy and PEAP

    EMPLOYEE
    Posted Aug 08, 2017 10:04 AM
    What are you using for a RADIUS server / policy engine?


  • 3.  RE: Acceptable Use Policy and PEAP

    Posted Aug 08, 2017 10:07 AM

    Sorry this was missing :-)

     

     

    Setup is 

     

    Aruba controller - Cleearpass 6.6.7 - AD

     

     

     Thanks 

     

    Erik Loeth

     

     



  • 4.  RE: Acceptable Use Policy and PEAP

    EMPLOYEE
    Posted Aug 08, 2017 10:11 AM
    Essentially you'll want to write a rule that checks for the prescense of a custom endpoint attribute. You can call it AUP or something. If not present or not equals true, return a captive portal redirect role to the controller.

    Anyone who has accepted the AUP will go right by past that rule and hit their rule in your policy.

    You'll also need to create a web login in Guest to handle the captive portal piece and a service that will accept the web login and stamp the endpoint with the AUP attribute.


  • 5.  RE: Acceptable Use Policy and PEAP

    Posted Aug 08, 2017 10:28 AM

    Somthing like this:

     

    IF AUP = false then apply role with vlan set to xx and a redirect role to the controller that point to the page to accept the AUP, thiss updates the endpoint with AUP=true

    do a coa.

    Now the AUP=true and only vlan xxx part is left, with access to all.

     

    Regads

     

    Erik Loeth

     

     



  • 6.  RE: Acceptable Use Policy and PEAP

    EMPLOYEE
    Posted Aug 08, 2017 11:10 AM

    Correct!



  • 7.  RE: Acceptable Use Policy and PEAP
    Best Answer

    Posted Aug 08, 2017 11:11 AM

    I will try this to morrow, and post the result.

     

    And again thanks for the help.

     

    Erik Loeth.

     

     



  • 8.  RE: Acceptable Use Policy and PEAP

    Posted Aug 18, 2017 06:34 AM

    Thanks for the help worked perfectley, the only thing i used some time on was updating endpoints from guest portal. but figured it out in another way.