Security

last person joined: 23 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Central WebAuth - Cisco Switches

This thread has been viewed 3 times
  • 1.  Central WebAuth - Cisco Switches

    Posted Mar 03, 2013 06:50 PM
    Is it possible to do central webauth with Cisco switches and Clearpass? It looks like only local webauth is possible and will require a separate "web login" for every switch that will have webauth enabled.


  • 2.  RE: Central WebAuth - Cisco Switches

    EMPLOYEE
    Posted Mar 13, 2013 01:25 AM

    What are you trying to accomplish?



  • 3.  RE: Central WebAuth - Cisco Switches

    Posted Mar 13, 2013 07:42 PM

    I need to setup webauth on 20 Cisco switches.  So I'm wondering if that means I need to create 20 web login pages in ClearPass.



  • 4.  RE: Central WebAuth - Cisco Switches

    Posted Mar 19, 2013 07:04 AM

    got no personal experience with this, but i would advise to ask this on a cisco forum also (if you haven't alread), lots depends on if you really need 20 different urls, if you do the question might be if clearpass can do something smart there.



  • 5.  RE: Central WebAuth - Cisco Switches

    Posted Mar 22, 2013 04:21 PM

    I ran into this issue as well in a proof-of-concept environment. For whatever it's worth, I had to put the guest traffic on a VLAN that spanned upstream to a untrusted port on an Aruba controller. It was at the Aruba controller that I applied a wired authentication profile, giving a role to those users. That role had a captive portal authentication profile, which redirected to CPPM for central web auth.

     

    FWIW, if you wanted to do this with Cisco ISE, you'd have to do things similarly for wireless users (i.e., have wireless guests be placed on a vlan, spanned upstream to an 802.1X enabled Cisco switchport wherein central webauth could be performed).

     

    Both CPPM and ISE have flaws when it comes to multivendor support for web auth.



  • 6.  RE: Central WebAuth - Cisco Switches

    Posted Mar 22, 2013 05:37 PM
    Ryan,

    That's a pretty good idea. I'll give that a shot and see how it works.


  • 7.  RE: Central WebAuth - Cisco Switches

    Posted Jun 05, 2013 09:03 PM
    .


  • 8.  RE: Central WebAuth - Cisco Switches

    Posted Jul 19, 2013 05:35 AM

    I think this will work with the web auth enforcment policy on the CPPM as there is a Cisco Web auth enforcment template in the Enforcment polices.

     

    The link below is how its done with ise (:smileymad:) and cisco switches. So I guess we can throw out ise and replace with CPPM with enforcment polices :smileyhappy: .

     

    http://www.cisco.com/en/US/products/ps11640/products_configuration_example09186a0080ba6514.shtml