Wireless Access

last person joined: 14 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Change Role of User Created in Guest Provisioning Portal

This thread has been viewed 4 times
  • 1.  Change Role of User Created in Guest Provisioning Portal

    Posted Mar 29, 2017 03:00 PM

    Wondering if there is anyway to adjust a Captive Portal Users role after they were created in the Guest Provisioning Portal and still allow them to be seen in that portal by the user that created it?  I did an import without issue of some users but wanted to modify the Role of the account I selected that from the drop down in the Internal DB but once I did that it disappeared from the user who created once I changed it back to the default Role and it the appeared back in their Portal to manage is there anyway that this can be done?



  • 2.  RE: Change Role of User Created in Guest Provisioning Portal

    Posted Mar 30, 2017 12:05 PM

    Hi,

     

    I am seeing similar behavior in lab & it might be expected.

     

    Could you please share the reason/use-case for changing the user-role for these users ?



  • 3.  RE: Change Role of User Created in Guest Provisioning Portal

    Posted Apr 11, 2017 09:24 AM

    Was looking at attaching a different role to apply different access controls such as App Access and Bandwidth Controls but the general staff would manage everything else via the GPP such as setup an account, manage credentials and expiration date.



  • 4.  RE: Change Role of User Created in Guest Provisioning Portal

    Posted May 02, 2017 12:33 AM

    Hi Evan,

     

    From a guest network perspective, you would apply same set of access policies/bandwidth control for each user.

     

    if yes, the role mapped in the captive profile could be changed to the role which will contain the required policies.

     



  • 5.  RE: Change Role of User Created in Guest Provisioning Portal

    Posted May 02, 2017 09:24 AM

    Hello,

     

      Downfall that I saw was once I defined that policy change by leveraging a Role Attribute to Set the new Role within the Server Group and then selecting that Role within the account it removed the user from view within the GPP for the Tech Staff to manage the account from expiration date, password or removing the account.  Only way they see it is if it is set to Guest Role which is the default role.  Are there any other options to do this type of control as ar as the role or is this one of those areas that has exceeded the basic function on the controller and Clear Pass is required?

     

       Thanks,

         Evan



  • 6.  RE: Change Role of User Created in Guest Provisioning Portal

    Posted May 03, 2017 04:32 AM

    Hi Evan,

     

    The user will only disappear from the GPP page if you will modify the role assigned to the user by navigating to internal database of the controller.

     

    You can map the required role (with controllers access) to the captive portal profile.

     

    The user will get this role post authenticating on the CP page.

     

    In this case, we do not have to make any changes to the user in the internal database.

     

    The role mapped to captive portal profile should override the role listed in the internal database automatically.

     

    In order to check the config that you have, please share the following outputs:

     

    1. show local-userdb | include <name of guest user>

    2. show aaa authentication captive-portal <name of profile>

     

    In the captive portal profile, you will see  a server group mapped to it.

     

    I need the following output as well:

     

    show aaa server-group <name of the group mapped in CP profile>