Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM and captive portal

This thread has been viewed 8 times
  • 1.  CPPM and captive portal

    Posted Apr 01, 2014 12:02 PM

    I have everything set up and working fine except CP through CPPM.  We can do the self registration portion and use internal users but I cannot get CPPM to use AD.  AD works fine for .1x through CPPM so it is a configuration of the captive portal service.

     

    Goal: users in AD can use AD to auth to an SSID which uses CPPM as the host of the CP.

    (cannot use controller for other reasons at this time).

     

    As soon as I press enter on the CP page (using my AD information), it returns bad username/password.  I do not see any thing logged on the CPPM either so I can't figure out where the problem is located.

     

    It all seems so simple but something is just not quite right.  I have AD added in all the places I think it should be... but no joy.

     

    Any ideas?



  • 2.  RE: CPPM and captive portal

    EMPLOYEE
    Posted Apr 01, 2014 12:04 PM

    On the Aruba Controller, your Captive Portal profile needs to have a server group that has CPPM in it.

     



  • 3.  RE: CPPM and captive portal

    Posted Apr 01, 2014 12:12 PM

    It has the CPPM server as the only server.  Is there something that needs to point the CPPM toward that Captive Portal Profile?

     

    The issue with the controllers, at this time, is the local CP has ip cp-redirect pointing to a controller (3600) for tunnel termination. It is an old design we will eventually fix but all 13 controllers point to this 3600 for guest access (not many guest).

     

    Since the current CPPM CP works with this in place, I do not think the ip cp-redirect is causing an issue.

     

     

    **EDIT**

    Found the 'pointer'.  In the initial role, we are pointing them to the correct Captive Portal profile.



  • 4.  RE: CPPM and captive portal

    EMPLOYEE
    Posted Apr 01, 2014 12:16 PM

    If it says bad username or password, something is rejecting it.  You are probably not configuring the correct captive portal authentication profile.  If you see a rejection and only cppm is in the server group, the rejection must come from cppm, period..



  • 5.  RE: CPPM and captive portal

    Posted Apr 01, 2014 12:28 PM

    **embarrassed**

     

    In my switch over from testing, I did not change the VAP we were using for the testing.  Unfortunately it now says web authentication is disabled.  I'll start working on that issue before I can get to authentication on the CPPM.

     

    *guessing this might be related to the ip cp-redirect*



  • 6.  RE: CPPM and captive portal

    Posted Apr 01, 2014 12:33 PM

    I understand your embarrassment, I do that a lot also.

     

    On the other hand, thanks for the topic, your discussion with Colin reminded me to check my own test turned production... I also am still using the test VAP. Or was until a moment ago.



  • 7.  RE: CPPM and captive portal

    Posted Apr 01, 2014 12:44 PM

    I have it corrected (web auth online) but it is back to 'invalid username or password' for all attempts with no log in the access tracker.



  • 8.  RE: CPPM and captive portal

    EMPLOYEE
    Posted Apr 01, 2014 12:47 PM

    What auth sources do you have in the service? Can you show a screen shot of the service?



  • 9.  RE: CPPM and captive portal

    Posted Apr 01, 2014 01:19 PM

    For both authentication and authorization, I have our AD as the target.



  • 10.  RE: CPPM and captive portal

    EMPLOYEE
    Posted Apr 01, 2014 01:46 PM

    It sounds suspiciously like it is trying to auth against the controller InternalDB.  Where did you put the server-group that has Clearpass in it?

     

    It needs to be in the captive-portal profile configuration.  If you are using the mach-caching with Clearpass, you need to put it as the 'mac-auth server-group' within the aaa-profile as well.



  • 11.  RE: CPPM and captive portal

    Posted Apr 01, 2014 02:44 PM

    I agree on all points made: it is not trying to talk with AD/Radius.  But why?

     

    Here's what I have from a flow chart perspective thus far:

     

    Initial role = CPG-login ; this gives the Captive Portal Profile = ClearPass_CP

    ClearPass_CP --> login page = http://x.x.x.x/guest/guest_register_login.php as well as Server Group = ClearPass (with CPPM server in it)

    Since ClearPass server/server group works with .1x, I do not believe that is the issue.

     

    Does the Policy Simulation work in CPPM?  I'm trying to make sure it hits my Service but I cannot get it to answer anything other than no policy matches.

     

    Service Rule (default for guest with MAC)

    IETF - Calling-station-Id - exists

    Connection - Client-MAC-Address  <> %{Radius:IETF:User-Name}

    Aruba - Aruba-ESSID-Name = OURssid

     

     

     

     

     



  • 12.  RE: CPPM and captive portal
    Best Answer

    Posted Apr 09, 2014 02:52 PM

    Found the issue.  It is hidden way down deep.  Took multiple Aruba engineers + others to finally find it.

     

    You have to turn off Pre-Auth in the guest management "NAS login".  Since AD is an external source, you don't do the pre-auth.



  • 13.  RE: CPPM and captive portal

    EMPLOYEE
    Posted Apr 01, 2014 01:21 PM
    Frankly if you are not seeing it in the access tracker, you first need to look at the controller.


  • 14.  RE: CPPM and captive portal

    Posted Apr 01, 2014 01:42 PM

    Double checking all of the controller config now. Would

     

    http://x.x.x.x/guest/guest_register_login.php

     

    still be the correct web url for the login page?