Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass integration

This thread has been viewed 1 times
  • 1.  Clearpass integration

    Posted Apr 07, 2014 05:22 AM

    Has anyone installed clearpass for guests in an autonomous AP environment?



  • 2.  RE: Clearpass integration

    MVP
    Posted Apr 07, 2014 05:30 AM

    yes, but you might want to include some more info or even your actual questions if you want to get a usefull answer.  :smileyhappy:



  • 3.  RE: Clearpass integration

    Posted Apr 07, 2014 05:38 AM

    I posted a specific question a while ago but there were no replies. What means is there for redirecting the guest to the clearpass portal if you have Cisco 1130 APs?.Centralized internet breakout onto the internet from guests at retail sites.



  • 4.  RE: Clearpass integration



  • 5.  RE: Clearpass integration

    Posted Apr 07, 2014 06:21 AM

    They are for controllers, Autonomous APs run without controllers.



  • 6.  RE: Clearpass integration

    MVP
    Posted Apr 07, 2014 06:32 AM

    appologies, I somehow ended up there searching for the AP you mentioned. As I already sais, no experience with those APs but it all boils down to whether or not they support external captive portals..

     

    Hopefully somebody else will be able to help you.



  • 7.  RE: Clearpass integration

    Posted Jul 08, 2014 07:17 AM
    Hi Matt, did you find a way to use the 1130 APs with clearpass? I have the same requirement.



  • 8.  RE: Clearpass integration

    Posted Aug 25, 2014 07:33 AM

    in cases like this the big question is if you can configure the AP for web authentication to an external URL. this has little to do with clearpass itself, that comes into play once you are able to redirect the client to it.

     

    i did a quick google search and couldn't find anything, so it might be this won't be possible.



  • 9.  RE: Clearpass integration

    Posted Aug 26, 2014 02:56 AM

    Sadly we haven't found a way round this. I image a program of upgrading the hardware over a period of time to Instants is what the customer will end up doing. If we do figure out a way round this I will update the post.



  • 10.  RE: Clearpass integration

    Posted Aug 26, 2014 08:07 AM

    As far as I can tell this isn't really a viable option when using the 1130 AP in autonomous mode. I can find some Cisco autonomous AP's that have this built-in functionality, but those run IOS 15.x.

     

    Only functionality that seems to be close in the 12.x is ip redirect:

    http://www.cisco.com/c/en/us/td/docs/wireless/technology/ip-redirect/technical/reference/ipredir.html

     

    I have no idea how to get it to stop redirecting tho.. 

     

    Some other references

    https://supportforums.cisco.com/discussion/11103646/captive-portal

    - Old, but same issue you're having.. No solution there either

     

    http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/116897-configure-technology-00.html

    - For IOS 15.x autonomous AP's

     

     

    And lastly - someone says this might be possible using some man-in-the-middle software:

    https://supportforums.cisco.com/discussion/11825651/autonomous-ap-web-authentication

     

     



  • 11.  RE: Clearpass integration

    Posted Aug 26, 2014 09:12 AM

    Might not work for the 1130's but I'm certainly going to get the latest code for a 2602 we have here and test this. I will update the post when I've done this. Thanks for the info.