Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Headless Authenticaion in CPPM 6.3 Guest

This thread has been viewed 0 times
  • 1.  Headless Authenticaion in CPPM 6.3 Guest

    Posted Apr 14, 2014 05:38 PM

    Hello,

    I am using CPPM 6.3.1 and want to create authentication for a printer, or any headless devices. 

    First I create the device in Guest:

    1.png

     

    In CPPM Authentication Sources only [Guest Device Repository] and [Guest User Repository] are used. 

    Assign role TIPS-HEADLESS if SponsorName EXIST  

    2.png

     

    Enforcement to return the HEADLESS role to controller

    3.png

     

    PROBLEM: the printer has never hit TIPS-HEADLESS role

    4.png

    Thanks.

     

     

     



  • 2.  RE: Headless Authenticaion in CPPM 6.3 Guest
    Best Answer

    EMPLOYEE
    Posted Apr 14, 2014 05:41 PM
    You need to do the guest device repository on a RADIUS MAC authentication
    service. Do you have a MAC check service?


  • 3.  RE: Headless Authenticaion in CPPM 6.3 Guest

    Posted Apr 14, 2014 05:52 PM

    Tim,

    Thanks for quick reply. Yes that is my problem. MAC AUTH added, and it works!!!!

    Capture.PNG

     



  • 4.  RE: Headless Authenticaion in CPPM 6.3 Guest

    EMPLOYEE
    Posted Apr 14, 2014 06:03 PM
    You should really separate out your MAC auth and web auth into separate
    services.

    You can use the service template "guest access with MAC caching" to do
    this.


  • 5.  RE: Headless Authenticaion in CPPM 6.3 Guest

    Posted Apr 15, 2014 12:16 PM

    Tim,

    I am very approciated you advice.  If you don’t mind, I’d like to follow up with a question: I am using guest to connect and authorize wireless printer.  Can I move printer to different VLAN after it was authenticated? 

     

    Best Regards,

     



  • 6.  RE: Headless Authenticaion in CPPM 6.3 Guest

    EMPLOYEE
    Posted Apr 15, 2014 12:34 PM

    With a MAC auth, yes.

     

    There are two ways of doing this:

     

    1) Create a printer user-role on the controller and attach a VLAN to it.

    2) Return a VLAN ID or VLAN name with an enforcement profile in your enforcement policy.

     

     



  • 7.  RE: Headless Authenticaion in CPPM 6.3 Guest

    Posted Apr 15, 2014 02:31 PM

    Score again.  Thanks Tim.

     

    I use #2, return VLAN ID from CPPM.  First an atribute "Aruba-User-Vlan" must be added to server group at the controller, then add VLAN ID to Enforcement profile.  Works like a champ!!!

    vlan.PNG