Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Can ClearPass be used as a policy manager for an existing Cisco AP and Controller deployment%3F

This thread has been viewed 0 times
  • 1.  Can ClearPass be used as a policy manager for an existing Cisco AP and Controller deployment%3F

    Posted Mar 21, 2014 03:41 PM


  • 2.  RE: Can ClearPass be used as a policy manager for an existing Cisco AP and Controller deployment%3F

    EMPLOYEE
    Posted Mar 21, 2014 04:08 PM

    Yes!  Absolutely.



  • 3.  RE: Can ClearPass be used as a policy manager for an existing Cisco AP and Controller deployment%3F

    Posted Apr 02, 2014 03:22 AM
    Are there any configuration guides or reference architecture documents that I might refer to?

    Regards,

    Mark


  • 4.  RE: Can ClearPass be used as a policy manager for an existing Cisco AP and Controller deployment%3F

    EMPLOYEE
    Posted Apr 02, 2014 03:30 AM
    You can work with your local SE and they can give you some samples. Currently there are not any official documents on wireless integration. Only wired which is on the support site under tech docs.

    You can also use. Https://ase.arubanetworks.com There is a config generator in there for Cisco wlc and CPPM.


  • 5.  RE: Can ClearPass be used as a policy manager for an existing Cisco AP and Controller deployment%3F

    Posted Apr 03, 2014 07:08 PM

    You can definitely do it and it's not much different to doint it with Aruba.

     

    I've got a customer running WLC's for ClearPass Guest and general 802.1x.

     

    You still define CPPM as the radius server in the WLAN profiles like you would with Aruba. The real changes are in how the guest stuff works. Cisco publishes an application note on the web redirect procedure. you need to push 2 Cisco VSAs out to trigger a captive portal redirect.  You can also specifiy the web login page in the WLC WLAN profile.

     

    see here for more info.

     

    http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/115951-web-auth-wlc-guide-00.html