Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Guest with mac caching and Cisco WLC

This thread has been viewed 9 times
  • 1.  Clearpass Guest with mac caching and Cisco WLC

    Posted Jan 23, 2015 04:41 PM

    Hi,

     

    Checking to see if anyone else has seen this type of issues with Cisco WLC & Clearpass guest:

     

    I have setup an open guest wlan on a Cisco WLC with Layer2 mac-filtering , Layer3 Web Policy/"On Mac failure" pointing to external ClearPass captive portal.  

    I used the templates to create the 2 services,

    -one with mac authentication accept if exists, reject if doesn't exist

    -WLC receives reject and sends user to Clearpass portal page to accept terms.

    -CPM radius reject delay is set to 0

     

    -The first time a user connects, the clearpass portal appears

    -user accepts terms,

    -instead of gaining access the Cisco internal web auth page appears.(no attributes set on endpoint)

    -user refreshes the browser, the Clearpass screen appears.

    -user accepts terms and gains access (attributes are set on endpoint)

     

    This can easily be reproduced. I've opened a Cisco TAC but waiting to work on it with them.

     

    Thanks,

    Jeanne



  • 2.  RE: Clearpass Guest with mac caching and Cisco WLC

    Posted Jan 23, 2015 05:29 PM
    Can you please share the error message if any ?

    Which attributes are you trying to use ?


  • 3.  RE: Clearpass Guest with mac caching and Cisco WLC

    Posted Jan 23, 2015 06:02 PM

    The templates set 2 attributes:

    Guest Role ID

    Username(which, in this case is the same for all guest because just accepting a policy)

     

    There isn't an error, other than the reject when the user is connecting the first time and mac address isn't cached already.

     

    To do a retest, we just clear the 2 attributes and can reproduce the problem.

     

    thanks

    Jeanne



  • 4.  RE: Clearpass Guest with mac caching and Cisco WLC

    Posted Jan 24, 2015 12:43 AM
    What Version WLC?

    You need to consider doing it with Central WEB auth. (Like ISE). I hated doing to with the on-Mac-failure.