Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Aruba Central with CPPM

This thread has been viewed 14 times
  • 1.  Aruba Central with CPPM

    Posted Sep 26, 2017 11:09 PM

    Hi ,

     

    I am new to Aruba , wondering if someone can answer these queries with explaination. 

     

    1. Can i integrate CPPM with Aruba central? If my Aps are spread across the globe and CPPM is in Data center. 

    2. In the same setup (Central with CPPM )can i use  AD,guest and on-board and on-guard services?

    3. If above is supported  and if i have 1000 Aruba central APs, how to i am going to add those as radius client in the CPPM server? Or i would need to create AP groups and make one of the AP as Virual controller.

     

    Could you please calify?

     

    Thanks in advance

     

    Regards,

    MD



  • 2.  RE: Aruba Central with CPPM
    Best Answer

    Posted Sep 26, 2017 11:39 PM
    1. Can i integrate CPPM with Aruba central? If my Aps are spread across the globe and CPPM is in Data center.

    You won't necessarily will be integrating central with ClearPass but you can push the config to the IAPs from Central so that IAPs can communicate with ClearPass .

    If the IAPs are able to talk to your ClearPass server in your DC then you shouldn't have any issues.

    2. In the same setup (Central with CPPM )can i use AD,guest and on-board and on-guard services?

    Same answer as the one above , the Aruba Instant will be the device interacting with ClearPass for (802.1X, Guest , Onboard) and the necessary configuration will be push from Central.

    3. If above is supported and if i have 1000 Aruba central APs, how to i am going to add those as radius client in the CPPM server? Or i would need to create AP groups and make one of the AP as Virual controller.

    What you can do is enable Dynamic RADIUS proxy (DRP) and that will allow you to use a single IP per IAP cluster as your RADIUS client in ClearPass
    http://community.arubanetworks.com/t5/Controller-less-WLANs/What-is-dynamic-radius-proxy-and-related-settings-in/ta-p/180918