Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CP OnBoard not redirecting to portal on single SSID

This thread has been viewed 1 times
  • 1.  CP OnBoard not redirecting to portal on single SSID

    Posted Jan 10, 2017 07:29 PM

    Hello, I configured a Single-SSID onboarding solution for a demo, Im using ClearPass 6.6.0.81015 and an Aruba 7005 as the controller.

    The user connects with credentials stored in the CP local DB to the SSID and once the web browser is opened it attempts to redirect to "https://<cp>/guest/device_provisioning.php" but after a few seconds it shows the "this page can't be viewed" (IE) or "ERR_TOO_MANY_REDIRECTS" (Chrome) error.

     

    Access Tracker shows an ACCEPT login status so, where could the issue be?

     

    Here is my Onboard configuration information:

    • Oboard is configured as Root CA.
      • Aruba Local Cert Auth.
    • Onboard Network Settings:
      • Network name: Segura Empleados.
      • SSID CP_Onboard configured.
      • Auto join checked.
      • TLS as Windows auth protocol.
      • Machine and user as Certificate store.
    • Onboard Config Profile Settings:
      • Networks: Segura Empleados.
    • Onboard Provisioning Settings:
      • name: Aprovisionamiento de dispositivos xxxxx.
      • Organization: xxxxx.
      • Cert Authority: Aruba Local Cert Auth.
      • Configuration Profile: Default.
      • Supported Devices: Win devices enabled.
      • Web login page>name: device_provisioning
      • Onboard Client>Provisioning Address: <ip of clearpass>(Management Port).
      • Validate Certificate: No, do not....

    Onboard Services on ClearPass:

    •  3 enforcement profiles:
      • Pre provisioning with Aruba controller firewall role of BYOD-Provision.
      • Post provisioning with Aruba controller firewall role of authenticated.
    • 3 enforcement policies.
    • 3 services.
    • 1 role mapping policy.

    Controller configuration:

     

    Any help would be greatly appreciated. Thank you



  • 2.  RE: CP OnBoard not redirecting to portal on single SSID

    EMPLOYEE
    Posted Jan 10, 2017 07:46 PM
    you need to add the clearpass IP to the logon role


  • 3.  RE: CP OnBoard not redirecting to portal on single SSID

    Posted Jan 11, 2017 11:57 AM

    Thank you Troy! I followed the steps on a Lab guide but the controller was preconfigured so I had to figure out what to do on that part.



  • 4.  RE: CP OnBoard not redirecting to portal on single SSID
    Best Answer

    EMPLOYEE
    Posted Jan 11, 2017 02:55 AM

    What is happening is that the requests going to your ClearPass server are redirected as well, that results in a redirect loop. As Troy mentioned, you need to create an exception to allow traffic to ClearPass without redirection in the role that users are in when they need to onboard.

     

    Check this article https://community.arubanetworks.com/t5/Community-Tribal-Knowledge-Base/Preventing-too-many-browser-redirects-during-guest-access/ta-p/17173, then the second half is how to configure your controller.



  • 5.  RE: CP OnBoard not redirecting to portal on single SSID

    Posted Jan 11, 2017 11:59 AM

    Thank you Herman, the link you provided was really helpful, my service is now redirecting to the portal.