Security

last person joined: 22 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

captive portal with ClearPass and Cisco WLC

This thread has been viewed 49 times
  • 1.  captive portal with ClearPass and Cisco WLC

    Posted Apr 17, 2015 06:34 AM

    Hi.

    I'm trying to setup wireless network for guests on Cisco 2504 WLC and I want to use captive portal on ClearPass (trial version) with self-registration. Because there so many options on ClearPass, I'm confused of how to configure controller and ClearPass and if it's necessary to use RADIUS. Right now I'm able to connect to guest network, request is redirected to captive portal where I can register. After registration, I can sign in successfully but then I'm redirected to 1.1.1.1 and I have no Internet access.

    Can someone give me instructions/guides how to set it up or where to look to find out why it's not working?

     



  • 2.  RE: captive portal with ClearPass and Cisco WLC

    Posted Apr 17, 2015 07:37 AM

    You may have already looked but the user guide is here.



  • 3.  RE: captive portal with ClearPass and Cisco WLC

    Posted Apr 17, 2015 08:25 AM

    Yes, I've already looked at user guide 6.5 (because this is the version I'm using) but it seems there are only general information. There are no details regarding my setup.



  • 4.  RE: captive portal with ClearPass and Cisco WLC

    Posted Apr 17, 2015 09:01 AM

    You will need to add ClearPass for Radius Authentication and Accounting.

     

    Are you using Mac Caching ?



  • 5.  RE: captive portal with ClearPass and Cisco WLC

    Posted Apr 17, 2015 09:32 AM

    I've already got RADIUS configured but I don't know if I have to associate it with Captive Portal.

     

    I didn't configure MAC Caching so it depends if it's enabled by default.



  • 6.  RE: captive portal with ClearPass and Cisco WLC

    EMPLOYEE
    Posted Apr 17, 2015 09:38 AM

    Over in ClearPass Guest, you need to make sure that you changed the NAS Login to Cisco for the Guest Self-Registration page.

     

    Some info about the Guest Login process:

     

    When you login, there are two things happening:

    1. Pre-auth check (we check to make sure the account is valid and not disabled)
    2. NAS Login (your browser does a POST to the Login Form on the controller at 1.1.1.1)

    When number 2 occurs, the controller should generate a RADIUS request to ClearPass.

     

    Other than that, you should be all set, as long as the request from the WLC hits the appropriate service in CPPM based on the service rules.

     

    Thanks,

     

    Zach



  • 7.  RE: captive portal with ClearPass and Cisco WLC

    Posted Oct 21, 2015 06:06 AM

    I had the same problem hereit stucked in login please wait and it shows in access tracker as acceppted but no thing happen.



  • 8.  RE: captive portal with ClearPass and Cisco WLC

    Posted Oct 21, 2015 08:35 AM
    You need to add the MAC address to the URL :
    <URL>.php?mac=%{Connection: Client-Mac-Address}


  • 9.  RE: captive portal with ClearPass and Cisco WLC

    Posted Oct 22, 2015 01:41 AM

    Hello Victor I added it on the redirection URL in Layer3 in WLAN and in web auth under security in controller and still the same I see in request it Identify the NAS as this

     

    Radius:Aruba:Aruba-Essid-NameGUEST
    Radius:Aruba:Aruba-Port-IdAloya
    Radius:IETF:Calling-Station-Id%{Connection: Client-Mac-Address} ?switch_url=https://1.1.1.1/login.html
    Radius:IETF:Event-Timestamp 
    Radius:IETF:Framed-IP-Address172.16.12.24
    Radius:IETF:NAS-IdentifierARUBA-CP
    Radius:IETF:NAS-IP-Address127.0.0.1
    Radius:IETF:NAS-Port0
    Radius:IETF:NAS-Port-Type15
    Radius:IETF:Service-Type17
    Radius:IETF:User-Nameadam@aloya.com


  • 10.  RE: captive portal with ClearPass and Cisco WLC

    Posted Oct 22, 2015 02:24 AM

    It Shows on clearpass accept request but after post authentication it redirect to this URL:

     

     

    http://1.1.1.1/login.html?redirect=redirect



  • 11.  RE: captive portal with ClearPass and Cisco WLC

    Posted Oct 24, 2015 02:34 PM

    Dear Please update me with following :

     

    what is the web login page NAS settings for cisco WLC is it the defaults and should I choose pre-auth RADIUS ? as when I didn't change it WLC did not send any request to Clearpass ?

     

    What is the right Service Template?

     

    Should I choose Vendor in Device Setting to be airspace or Cisco?

     

    what is the right Pre-Auth ACL as I created it to be the same as Amigopod guide?

     

     



  • 12.  RE: captive portal with ClearPass and Cisco WLC

    Posted Aug 07, 2019 03:04 AM

    Did you find on this the solution? I have exactly the same problem.



  • 13.  RE: captive portal with ClearPass and Cisco WLC

    Posted Oct 10, 2017 06:16 AM

    i have exactly same issue.

    please update on how you resolve this issue?



  • 14.  RE: captive portal with ClearPass and Cisco WLC

    Posted Nov 14, 2019 01:36 PM

    Not sure if its related but the 2504 does not support a redirect to a URL post authentication.