Security

last person joined: 18 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Guest with Meraki Wireless

This thread has been viewed 27 times
  • 1.  ClearPass Guest with Meraki Wireless

    Posted Feb 06, 2019 11:55 AM

    Does anyone have an end to end guide on how to set up ClearPass guest captive portal with Meraki Wireless?  I have set up a guest SSID within Meraki wireless and configured as a splash page with custom splash page. When the client connects to the SSID the captive portal page from clearpass loads up.  The user tries to self register, and the guest account gets created in ClearPass.  When the user tries to login, the browser is just getting directed to a Meraki 'page not found' page.  

     

    Within Meraki the RADIUS transaction for the guest captive portal comes from the Meraki Cloud not the AP IPs.  

     

    I dont seem to have the correct NAS vendor setting for the Meraki Cloud in order to POST the user credentials to the controller.   The RADIUS request never gets to ClearPass from the controller.  

     

    Has anyone had a successful implementation with Meraki?

     

    Thanks

     

     



  • 2.  RE: ClearPass Guest with Meraki Wireless

    EMPLOYEE
    Posted Feb 06, 2019 12:01 PM

    You need to use the "Cisco Identity Services Engine (ISE) Authentication" option with a ClearPass MAC auth and WEBAUTH service. The MAC auth service should return back a captive portal URL using a Cisco AV-Pair and the WEBAUTH service should issue a Disconnect after succesful authentication.



  • 3.  RE: ClearPass Guest with Meraki Wireless

    Posted Feb 06, 2019 01:06 PM

    Thanks Tim!  We finally got it going!



  • 4.  RE: ClearPass Guest with Meraki Wireless

    Posted Feb 06, 2019 02:08 PM

    OK we thought we had it going, if I set the pre-auth check on the registration page to RADIUS, I get a RADIUS request come into ClearPass.  Even if we send an Accept Message and CoA, the client never gets connected to the network.  

     

    Is there a setting I need to implement in order to get the request to come in as a WebAuth instead of RADIUS?

     

    Thanks Again



  • 5.  RE: ClearPass Guest with Meraki Wireless

    EMPLOYEE
    Posted Feb 06, 2019 02:13 PM
    In the vendor settings, select Cisco and Server-Initiated.


  • 6.  RE: ClearPass Guest with Meraki Wireless

    Posted Feb 11, 2019 03:50 PM

    Hi Tim, 

     

    Thanks again for all the great info, we have this set up and essentially working at this point.  However the end user experience is not very clean.  Since we are issueing a COA after the webauth, the browser is essentially still finishing the login process (please wait while you are logged into the network).  The browser throws an error since we are sending the COA while its loading.  The re-auth (MAC auth) then takes place and the user is connected.  From the end user perspective, it looks like they are not connected since the browser errors and just hangs there.  

     

    Do you have any thoughts on how to clean up that process to the end user?

     

    Thanks

     



  • 7.  RE: ClearPass Guest with Meraki Wireless

    EMPLOYEE
    Posted Feb 11, 2019 04:03 PM
    You should be using a Disconnect, not a CoA. In the web login configuration, you can increase the login delay to accommodate for the network change.


  • 8.  RE: ClearPass Guest with Meraki Wireless

    Posted Feb 11, 2019 04:48 PM

    The only two types of Enforcement profiles that you can select with the Webauth Service is Post Authentication or CoA.  

     

    Here is what we are currently sending 

     

    Screen Shot 2019-02-11 at 1.45.19 PM.png

    Is there a different type of disconnect we should be sending?

     

    Thanks

     



  • 9.  RE: ClearPass Guest with Meraki Wireless

    EMPLOYEE
    Posted Feb 11, 2019 04:51 PM


  • 10.  RE: ClearPass Guest with Meraki Wireless

    Posted Feb 11, 2019 05:08 PM

    When I try to import that template, i get an error that Vendor ID 29671 is not a valid vendor ID.  Is that supposed to be the Vendor ID for Meraki?

     



  • 11.  RE: ClearPass Guest with Meraki Wireless

    EMPLOYEE
    Posted Feb 11, 2019 07:35 PM
    Are you running ClearPass 6.7 or higher?


  • 12.  RE: ClearPass Guest with Meraki Wireless

    Posted Feb 12, 2019 02:41 PM

    Yes we are running 6.7.9 and I think we finally got it working with the re-authenticate session, audit session ID and increasing the login delay time on the captive portal page.

     

    Thanks for all your great assistance!



  • 13.  RE: ClearPass Guest with Meraki Wireless

    Posted Feb 27, 2019 10:44 AM

    Did you get it working with windows 10 laptops as well?

     

    I got it working on smartphones using the reauthentication command and audit-session-id as well. But a laptop just remains connected. 

     

    I tried the disconnect as well. Using the Acct-Session-Id and timestamp but nothing seems to work. The laptop just won't disconnect.



  • 14.  RE: ClearPass Guest with Meraki Wireless

    Posted Feb 13, 2020 06:16 PM

    Did you find anything to help you start to setup the services?  I need to only allow employees on a SSID for Meraki but don't know how to start.  Do you guys use 802.1X Wireless?  or something else?  We are not doing a captive portal, just using their domain credentials at this time.  Is there anything I can look at about setting up wireless with meraki or something other than Aruba access points?