Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Use Clearpass to change Vlan Device in

This thread has been viewed 7 times
  • 1.  Use Clearpass to change Vlan Device in

    Posted Jun 14, 2013 01:49 PM

    We have Clearpass Guest and am trying to force clerapass to change the VLAN once the User is Authenticated (same SSID).  I can see that in the Output the New VLAN ID is passed back but doesn't seem to make a difference and the IP address is not changed.

     

    Is this possible?  Ifo so, what am I doing wrong?

     

     



  • 2.  RE: Use Clearpass to change Vlan Device in

    Posted Jun 14, 2013 01:56 PM

    Hey,

     

    I could be wrong about this, but I don't think the change of VLAN's will work without a client first diconnecting then reconnecting.

     

    For our Onboard we are using two different SSID's and we are able to move users between VLAN's (from provisioning VLAN to BYOD VLAN) without an issue. But in this situation the client gets disconnected then is reconnected.

     

    Is there any specific reason you don't want to leave your Guests in the same VLAN?

     

    You can leave them in the same VLAN but just have two different roles, an unauthorized role and an authorized role.



  • 3.  RE: Use Clearpass to change Vlan Device in

    EMPLOYEE
    Posted Jun 14, 2013 02:39 PM

    You would need to add an enforcement policy with a RADIUS Change of Authorization which will disconnect them allowing them to reconnect in the new VLAN assigned in the policy.



  • 4.  RE: Use Clearpass to change Vlan Device in

    Posted Mar 05, 2018 07:16 PM

    does CoA work with software version below 16.02 on an Aruba 5402zl2? if not, what alternative do i have , roles?

     

    thanks



  • 5.  RE: Use Clearpass to change Vlan Device in

    EMPLOYEE
    Posted Mar 05, 2018 07:19 PM
    What are you trying to do?


  • 6.  RE: Use Clearpass to change Vlan Device in

    Posted Mar 05, 2018 07:22 PM

    802.1x wired with an HPE 5402ZL2, dynamic vlan assigment based on user group in AD.

     

    802.1x works, it gets the right policy based on user, but when the profile tries to assign the vlan nothing happens, the user sits on the vlan currently assigned on the switch.

     

    I am trying to figure out how to dynamically assign vlan from Clearpass.

     

    thanks



  • 7.  RE: Use Clearpass to change Vlan Device in

    EMPLOYEE
    Posted Mar 05, 2018 07:32 PM
    I’d recommend following the doc and setting up user roles.