Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Wireless using Meraki

This thread has been viewed 12 times
  • 1.  ClearPass Wireless using Meraki

    Posted Feb 13, 2020 06:25 PM

    Is there any guides for setting up ClearPass with other vendor's wireless access points?



  • 2.  RE: ClearPass Wireless using Meraki

    Posted Feb 13, 2020 07:09 PM

    Hi,

     

    If you just need WPA2-Enterprise using clearpass policy manager with meraki then it is pretty simple. 

     

    For Meraki you need to go to Wireless-> Configure -> SSID.
    Create a new SSID or edit an existing one.
    Under "Network Access" select Enterprise and in the dropdown box next to it, select "My radius server".
    Then scroll down and you'll see "radius server". Just add the clearpass server, port 1812 and your shared secret.

     

    In clearpass just create a generic 802.1x wireless policy. 
    Just be aware that your radius requests will come from each Meraki AP. So you need to add all the AP's as a radius device in clearpass. Or use a subnet. All AP's should have access to the clearpass appliance at port 1812. The vendor code you need to select is Cisco.

     

    If you want more details, I can check the configuration I have running with customer tomorrow.



  • 3.  RE: ClearPass Wireless using Meraki

    Posted Feb 14, 2020 09:31 AM

    Thank you for that information.  It helped get started.  But I am not sure what to do for the enforcement profiles.  I assume I can do a generic SSID, then depending on what shows up as the roles, it can move them to different SSIDs and VLANs depending on where they are connecting from?  The Wired portion had a whitepaper to work with cisco and that gave me what I needed to figure out how to setup the Enforcement Profiles for all my wired equipment, but wireless there doesn't seem to be anything for Cisco?