Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Onboarding IOS Devices with Single SSID

This thread has been viewed 1 times
  • 1.  Onboarding IOS Devices with Single SSID

    Posted Oct 10, 2013 06:25 AM

    Hi All,

     

    I've got clearpass configured to onbaord IOS devices using a single SSID.This works fine but what I'd like to happen is at the endof the onbaording process for the iPad to be in the correct role.

     

    I'm sure I can do this with a RADIUS CoA right?

     

    Cheers

    James



  • 2.  RE: Onboarding IOS Devices with Single SSID

    Posted Oct 10, 2013 06:27 AM

    Nevermind, I think I've got it.

    I'll just add a CoA to my byod role on the Onboard Authorisation service.



  • 3.  RE: Onboarding IOS Devices with Single SSID

    EMPLOYEE
    Posted Oct 11, 2013 01:46 AM

    James,

     

    Make sure in your controller you enable the add switch ip. If that is not checked then the auto reconnect or the connect button will not show up. You should not have to set a bounce for IOS devices.

     

     

     

    screenshot_13 Oct. 11 00.28.gif

     

     

    screenshot_14 Oct. 11 00.38.gif

     



  • 4.  RE: Onboarding IOS Devices with Single SSID

    MVP
    Posted Oct 13, 2013 05:33 AM

    As tarnold says, you do not need to configure the coa manualy anywhere. It is 'hardcoded' in the process.

    You do need to make sure however that your coa is received correctly on your controllers.

     

    Check this with the following commend: show aaa rfc-3576-server statistics.

     



  • 5.  RE: Onboarding IOS Devices with Single SSID

    Posted Apr 21, 2014 09:18 PM

    Hi,

     

    I'm looking to do the same sort of configuration, I have CP working for provisioning but I can't see to get the two roles working depending on if you join the SSID via AD credentials or join the same SSID with TLS and a provisioned cert.

     

    Effectivitly AD auth -> provisioning role and redirect to CP device enrollment page

    EAP-TLS -> auth certificate -> full access role

     

    Is there a guide I can follow?

     

     



  • 6.  RE: Onboarding IOS Devices with Single SSID

    EMPLOYEE
    Posted Apr 22, 2014 12:07 AM