Wired Intelligent Edge

last person joined: yesterday 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

Wired Authentication

This thread has been viewed 7 times
  • 1.  Wired Authentication

    Posted May 08, 2013 06:59 PM

    We are about to roll out Aruba switches to replace some old HP switches.  I'm hoping we can allow people to plug it and attempt to use .1x authentication and if that fails use a captive portal to connect to the guest network.  Is this possible with ClearPass, controller and switch deployment?

     

    Thanks!



  • 2.  RE: Wired Authentication
    Best Answer

    EMPLOYEE
    Posted May 08, 2013 07:07 PM

    Hi Jaker,

    The short answer is yes it is. The way I would configure it is that the AAA Profile is configured with MAC-Auth and Dot1x and an initial role of denyall. The denyall user role will prevent the client from getting an IP address until it passes authentication which is useful to ensure that even if you switch VLANs on the client based upon authentication, it doesn't have the IP from the initial role VLAN even after you changed VLANs. You would then write a rule on ClearPass that if the MAC is unknown then send it to a user-role on the MAS that is configured with a Captive Portal.

     

    Best regards,

     

    Madani



  • 3.  RE: Wired Authentication

    Posted May 09, 2013 08:11 AM
    As it is stated in the previous comment it is possible. I just want to note that you can also do this without using clearpass.


  • 4.  RE: Wired Authentication

    EMPLOYEE
    Posted May 09, 2013 09:55 AM

    Good point zshusveti! We added native captive portal support to the MAS in AOS 7.2.



  • 5.  RE: Wired Authentication

    Posted May 09, 2013 10:06 AM

    Thanks for the direction on how to work on this.  I'm new to ClearPass and the switches so I'm going to work on it over the new few weeks.   I might be back if I run into issues.