Security

last person joined: 9 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Cluster with more than one VIP for NAD Load-Balancing

This thread has been viewed 5 times
  • 1.  ClearPass Cluster with more than one VIP for NAD Load-Balancing



  • 2.  RE: ClearPass Cluster with more than one VIP for NAD Load-Balancing
    Best Answer

    EMPLOYEE
    Posted Nov 20, 2018 04:47 PM

    Let me try to understand:

     

    You typically have to create a VIP between two clearpass nodes when you have a URL that only resolves to a single ip address like an initial guest page.   You make the URL resolve to the VIP address and the redundancy is provided by the VIP between the two servers.

     

    On the other hand, if you want to do redundancy for a NAS where you can specify a primary and a secondary ip address for radius servers, you specify the literal ip addresses and not the VIPs.  The NAS would manage the redundancy by always choosing the first ip address or load balancing between the two radius servers based on how the NAS is configured.  Typically a NAS that does load balancing knows how to detect if a node is "alive" or not.  If you choose the point the NAS at VIPs, instead, there will be no load balancing, because whichever ClearPass node "owns" the VIP will always take the load.

     

    You can choose either way based on your requirements, but If you point a NAS at a VIP, there will be no load balancing, at all.



  • 3.  RE: ClearPass Cluster with more than one VIP for NAD Load-Balancing

    Posted Nov 21, 2018 10:29 AM

    Hi and thanks for quick reply.

     

    I know that using the "real" IP-Adresses is the common best practise.

    To be honest, I just found another Thread with the exact same question.

     

    https://community.arubanetworks.com/t5/Security/CPPM-Virtual-IP-for-Captive-Portal-and-RADIUS/td-p/267500

     

    regards