Security

last person joined: 19 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM - Prevent Guest users from logging on to certain captive portal

This thread has been viewed 0 times
  • 1.  CPPM - Prevent Guest users from logging on to certain captive portal

    Posted Apr 24, 2017 04:03 PM

    Hi Airheads!

     

    We have a CPPM implementation with a Clearpass cluster in a central location with multiple branch offices with local Aruba wireless controllers. We have different captive portals (14 in total) implemented, 2 per remote site (one for visitors, one for patients). There are also 2 SSID's per remote site.

    Each portal has its own GuestUser Role ID assigned so that we can make a difference between the different guest users and thus assign the appropriate Aruba user role back to the controllers.

     

    There is however one problem: guest users are able to login to both the portal for visitors and to the portal for patients. And that is not the purpose...

     

    The question is: how can we prevent guest users intended for e.g. the visitor portal to log on to the patients portal?

     

    Thanks in advance!

     

    Best regards

    Tim



  • 2.  RE: CPPM - Prevent Guest users from logging on to certain captive portal

    EMPLOYEE
    Posted Apr 24, 2017 04:57 PM

    What is the access difference between patients and guests?



  • 3.  RE: CPPM - Prevent Guest users from logging on to certain captive portal

    Posted Apr 24, 2017 05:08 PM
    Guests are allowed restricted internet-only access, patients can additionally browse to some internal resources. These access restrictions are configured on the wifi controllers


  • 4.  RE: CPPM - Prevent Guest users from logging on to certain captive portal

    Posted Apr 24, 2017 05:56 PM

    how are you making the distinction between  the two type of users?

     

     

     

     



  • 5.  RE: CPPM - Prevent Guest users from logging on to certain captive portal

    EMPLOYEE
    Posted Apr 24, 2017 07:00 PM
    Why not use the same SSID and use role based access?


  • 6.  RE: CPPM - Prevent Guest users from logging on to certain captive portal

    Posted Apr 24, 2017 11:54 PM
    The customer insisted on different SSID's instead of one.


  • 7.  RE: CPPM - Prevent Guest users from logging on to certain captive portal

    Posted Apr 24, 2017 11:53 PM
    We've made different guest user role ID's per type of user, 14 in total. This way we do the role mapping to differentiate the type of users.


  • 8.  RE: CPPM - Prevent Guest users from logging on to certain captive portal
    Best Answer

    Posted Apr 27, 2017 10:16 AM

    Solved by checking for the according SSID in combination with the assigned Role ID to the Guest account.