Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

This thread has been viewed 0 times
  • 1.  Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    Posted Apr 24, 2018 02:31 AM
      |   view attached

    I am working on a POC of a solution that will be provide WiFi coverage by deploying Aruba instant access points (IAP) in 100 plus sites.On each site Internet will be provided by 4G Modem Dongles connected to USB port of an Access Point. All IAPs will be managed by Aruba Central and Guest Wi-Fi services will be provided by ClearPass Guest.

     

    Network Diagram

     

    Figure-1.png

    User Connectivity Flow

     

    1. User connects to Visitor SSID.
    2. SSID will automatically redirect to ClearPass Captive Portal Page.
    3. User have to click on “Please click here to Register yourself” to submit user information.
    4. User will then submit a form.
    5. User will then be redirected to demo.feag-games.com.

    For POC demonstration we don’t have public IP addresses so we are working on the following way around.

     

    Figure-2.png

     

    But in this scenario we are facing issues as when a user connects to the SSID it only assigns user IP address and did not redirect user to the ClearPass captive portal for authentication as a result user remains in Pre authentication role.

     

    If we remove 4G Dongle then everything works fine.

     

    Figure-3.png

    I have also attached user connectivety flow document.

    Attachment(s)



  • 2.  RE: Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    MVP EXPERT
    Posted Apr 24, 2018 02:34 AM
    When the client is facing the issue, are they able to perform a nslookup and receive a response from a working DNS server? The Captive Portal re-direct will not work if there is no valid DNS server.


  • 3.  RE: Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    Posted Apr 24, 2018 03:41 AM

    Hi 

     

    Yes user is geting  response from 4G Modem DNS server.

    nslookup.png



  • 4.  RE: Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    MVP EXPERT
    Posted Apr 24, 2018 04:16 AM
    Do you see this in the datapath? What do you have configured in your
    initial role?


  • 5.  RE: Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    Posted Apr 24, 2018 04:26 AM

    Below is the configuration of Preauthentication role.

    192.168.1.251 is CPPM IP address on LAN.

    pre-auth.png



  • 6.  RE: Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    Posted Apr 24, 2018 04:28 AM

    Below is the configuration of Preauthentication role.

    192.168.1.251 is CPPM IP address on LAN.

    pre-auth.png



  • 7.  RE: Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    MVP EXPERT
    Posted Apr 24, 2018 04:39 AM

    Hi, in your nslookup screenshot it does not show if the client is able to successfully perform a nslookup whilst in your initial role.


    Do you see the User Traffic arriving at the CPPM when the issue occurring? You can run a packet capture under Server Configuration to confirm this.



  • 8.  RE: Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    Posted Apr 24, 2018 04:49 AM

    This is the detail answer to your question regarding DNS.

    nslookup2.pngnslookup3.png



  • 9.  RE: Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    MVP EXPERT
    Posted Apr 24, 2018 04:57 AM

    Hi, in the latest screenshots DNS does not appear to be working. Can you set the client to use a public DNS such as 8.8.8.8 and test again? 



  • 10.  RE: Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    Posted Apr 24, 2018 05:02 AM

    To be on the same page below is network diagram of the setup.

     

    Figure-2.png



  • 11.  RE: Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    Posted Apr 24, 2018 05:15 AM

    Below is the result after changing DNS to 8.8.8.8

    nslookup4.png

     



  • 12.  RE: Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    EMPLOYEE
    Posted Apr 24, 2018 06:05 AM

    Can the wireless client browse to the ip address of the clearpass server using http or https?

     

    EDIT:

     

    Your POC design needs to allow the client to be able to browse to the ip address of clearpass and bring up the page via https://<ip address of clearpass>/guest/blahblah, before DNS even comes into play. 

     

    Ultimately to make this solution work with 100 sites, you might have to have  to consider ClearPass be on the public internet so that it would be reachable by 100 sites that only have connectivity via a 4g dongle.



  • 13.  RE: Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    Posted Apr 24, 2018 06:21 AM

    No it cannot browse to clearpass IP in initail role.

     

    Yes you are right but for the POC purposes wolud this POC is possible to work without Public IP addresses.

    I am working on this setup.

    Figure-2.png

    When i use below setup every thing works fine.

    Figure-3.png

    For the reference AP ip address configuration is mentioned below.

     

    jazz-1.png



  • 14.  RE: Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    EMPLOYEE
    Posted Apr 24, 2018 06:37 AM

    Can you SSH into the access point and ping the clearpass server?  Your POC design is complicated by having a dual-connected access point.



  • 15.  RE: Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    Posted Apr 24, 2018 06:43 AM

    Yes CPPM is pingable from IAP.

     

    jazz2.png



  • 16.  RE: Unable to redirect users to ClearPass Captive Portal when using 4G Dongle as Uplink

    EMPLOYEE
    Posted Apr 24, 2018 06:51 AM

    You should attempt to browse to the clearpass server from the wireless client (https://<ip address of clearpass server) and type "show datapath session" on the IAP to see what happens to the client traffic.

     

    Ultimately you should  work with a ClearPass Partner on your POC design to come up with something scaleable that meets your requirements.  It is difficult  to help someone trobleshoot a problematic design.