Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass dual guest networks, service issue

This thread has been viewed 0 times
  • 1.  Clearpass dual guest networks, service issue

    Posted Mar 13, 2017 03:59 AM
      |   view attached

    One of our client (an municipal county) wants to use 2 different guest networks, one for guests visiting the county officials and one for students at a senior high school. On the student guest network there must be a limit of one device per user. Our client does not have an on-boarding license (nor do they have the founds to purchase one at the moment).

     

    I have created 2 different services (see the attachment for more information on one of the services). I have created a new role for the new guest network, have edited the enforcement profile (denying the
    county guest role from accessing the student guest network and vice versa. But....still a county guest user account is still able to login to the student guest network. I am missing something, but I do not know what I am missing...any help will be very helpful. I can add more screen shots if needed.



  • 2.  RE: Clearpass dual guest networks, service issue

    Posted Mar 13, 2017 07:30 AM
    How are the users registration into each captive portal ?

    Essentially you need to find a way to differentiate between each type of user otherwise there's no way to prevent / deny access based on the type of users

    Get Outlook for iOS


  • 3.  RE: Clearpass dual guest networks, service issue

    Posted Mar 13, 2017 07:46 AM

    I am not sure if I understand you correctly but....when a guest user is created the creator chooses which type of user (Employee, Contractor, Guest or Gymnasie-Guest) she/he wants to create and thus the newly created user receives the proper role. If this is not what you meant, can you please be more clear...thanks (english is not my native language).

     

    Software version on the CP is: 6.6.2, we are planning an upgrade since the client experiences many strange problems/issues...



  • 4.  RE: Clearpass dual guest networks, service issue

    EMPLOYEE
    Posted Mar 13, 2017 07:33 AM

    Are you assigning different role IDs in your two guest forms?

     



  • 5.  RE: Clearpass dual guest networks, service issue

    Posted Mar 13, 2017 07:54 AM

    Yes, we are.



  • 6.  RE: Clearpass dual guest networks, service issue
    Best Answer

    Posted Mar 15, 2017 03:41 AM

    Well this problem has been solved, most likely due to improper testing procedures (from our client). So the configuration that I attached in my first post do work.