Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Preferred way to set airgroup_shared_location-id Ap-group?

This thread has been viewed 1 times
  • 1.  Preferred way to set airgroup_shared_location-id Ap-group?

    Posted Nov 19, 2018 10:04 AM

    Looking through the docs I can log into a controller and for an airgroup service do an "autoassociate apgroup"

     

    What if I wanted to do this from clearspass? Would that be the same as setting  airgroup_shared_location = "AP-Group=......" ?

     

    Basially if a device logs onto an SSID just want them to see airgroup servers on the same ap-group.

     

    A



  • 2.  RE: Preferred way to set airgroup_shared_location-id Ap-group?

    EMPLOYEE
    Posted Nov 19, 2018 10:07 AM
    Yes, you just select the AP group or AP name during device registration.


  • 3.  RE: Preferred way to set airgroup_shared_location-id Ap-group?

    Posted Nov 19, 2018 10:10 AM

    so what about when its an end user and we are trying to minimise the amount of stuff they have to type? You wouldn't want an end user to have to pick an ap group, you;d want to set it automagically.

    A



  • 4.  RE: Preferred way to set airgroup_shared_location-id Ap-group?

    EMPLOYEE
    Posted Nov 19, 2018 10:11 AM
    Auto RF neighborhood (Controller) and device registration (ClearPass) are mutually exclusive today.


  • 5.  RE: Preferred way to set airgroup_shared_location-id Ap-group?

    Posted Nov 19, 2018 10:18 AM

    o.k. so then i want to use the clearpass guest airgroup_shared_location value ( which I've currently got disabled in my form). Two questions:-

    1). 

    But setting that would tie devices to wherever you 1st configured them. I know that this is probably the right thing to do, but what if these devices were portable and you moved them from one AP group to another? I'd sort of expect to be able to have clearpass send appropraite shared location stuff based upon where a device is.

    2). If I was to use airgroup_shared_location, is there an automagic way of setting it to the ap group that the ap the device is connected to is in?

     



  • 6.  RE: Preferred way to set airgroup_shared_location-id Ap-group?

    Posted Nov 19, 2018 10:47 AM

    Guess what you want to do is set the initial value of airgroup_shared_location to be the ap group you are currently connected to

     

    Can you do that?

    A



  • 7.  RE: Preferred way to set airgroup_shared_location-id Ap-group?

    EMPLOYEE
    Posted Nov 19, 2018 10:52 AM
    No. That's now how the feature is designed.


  • 8.  RE: Preferred way to set airgroup_shared_location-id Ap-group?

    Posted Nov 19, 2018 10:56 AM

    Ah! 

    So guess I'm back to autoassociate on the mobility controller then

     



  • 9.  RE: Preferred way to set airgroup_shared_location-id Ap-group?

    EMPLOYEE
    Posted Nov 19, 2018 10:57 AM
    Most end users want to access their own services anywhere on campus. That is the way the feature was designed.


  • 10.  RE: Preferred way to set airgroup_shared_location-id Ap-group?

    Posted Nov 19, 2018 11:10 AM

    And just discovered that the way we create AP Groups makes it impractical to evem think of this :-(