Security

last person joined: 21 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Captive Portal over non Management IP

This thread has been viewed 2 times
  • 1.  Captive Portal over non Management IP

    Posted Jan 28, 2019 04:19 PM

    I have a public guest network, that uses a controller based captive portal for acces.  The IP addresses that the guest network use is totally seperate from my production wirless, however the IP address captive portal is hosted on by default is the management IP address of the controller. Therefore I have to allow access from my Guest network to my controller which I prefer not to do.


    I have assigned an IP address to my guest network vlan, and would like to have the captive portal accessed via this IP address instead of the management IP address as the guest network will have access to itself already.

    Is it possible, and if so how can i change which IP address my guest network captive portal is hosted on?



  • 2.  RE: Captive Portal over non Management IP



  • 3.  RE: Captive Portal over non Management IP

    Posted May 08, 2019 02:10 PM

    I tried to set the CP-redirect-address to the IP address that is assigned to the vlan on my controller in my guest network.


    I run this command.
    ip cp-redirect-address 10.30.0.254   

    It appears to run but nothing changes when I connect to my guest network, it still loads the Captive portal page on my management interface  10.50.0.25

    any Ideas?



  • 4.  RE: Captive Portal over non Management IP

    EMPLOYEE
    Posted May 08, 2019 11:19 PM

    Is 10.30.0.254  in the same subnet as your guest network?



  • 5.  RE: Captive Portal over non Management IP

    Posted May 09, 2019 10:34 AM

    Yes, my guest vlan is 30, which gives out addresses below 10.30.0.200 via dhcp.  I added vlan 30 to my controller and assigned 10.30.0.254. I ran the specified command from the CLI on the Mobility master, it won't let me run it directly on the controller while its managed. 

    My captive portal still loads on my mangagement IP address.  It works because I allowed that traffic, I would just very much like to not have my public guest network be able to hit anything in my production networks.

     

    Thanks!

    Darron