Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Unable to get provisionning profile for wireless clients

This thread has been viewed 0 times
  • 1.  Unable to get provisionning profile for wireless clients

    Posted Dec 15, 2017 11:27 AM

    Hello all. I'm doing single SSID provisionning using Clearpass and a Cisco WLC.

    So far I'm able to redirect clients, download QuickConnect (only on windows, android doesn't work for some reason. I'm focusing on windows laptos for now) The certificate is provisioned and I can see it in the onboard lists. HOwever, when I get to the point to connect to the network It sits there and doesn't connect. I used the onboard wizard to create the services and I'm not sure where I went wrong. I just don't see the provisionning Service triggering in Access Tracker. My configs are attached for authorization and provisionning.

     

    Pre auth works, as I do get the download. Just not sure if something is missing.

     

    The objective is to get the users onboarded and then sent to a specific VLAN via de Cisco WLC. Which are mapped in the Asigna VLAN policy assigned in Provissioning service...

     

    I hope you can help me since this has been a headache for me for some time now.

     

     

     

     

    Attachment(s)

    pptx
    airheads1.pptx   250 KB 1 version
    txt
    log onboard.txt   65 KB 1 version


  • 2.  RE: Unable to get provisionning profile for wireless clients

    Posted Dec 17, 2017 09:26 PM
    When the device is trying to connect to The ssid after it was provisioned do you see anything in Access tracker ?

    You need a service that it supports 802.1X with EAP-TLS

    Get Outlook for iOS


  • 3.  RE: Unable to get provisionning profile for wireless clients

    Posted Dec 18, 2017 05:21 PM

    I was able to finally map the users to the provisionning service by creating a Cisco-AV pair enforcement. HOwever. the controller is not quiting the "Requires Web-Auth" profile. And keeps redirecting to the captive portal, so I can't log in. I've gone through the guides available from clearpass step by step... but it doesn't seem to be working...