Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass and iAP - mac-auth with multiple VLAN enforcement

This thread has been viewed 24 times
  • 1.  ClearPass and iAP - mac-auth with multiple VLAN enforcement

    Posted Mar 25, 2019 10:09 AM

    Hi,

    I need an advice with HPE 5130EI switch and multiple VLAN (tagged and untagged) enforcement from ClearPass. On ArubaOS switches it is working well with Attribute HPE-Egress-VLAN-Name/ID but I cant find anything like this for Comware (H3C) switches.

     

    Is there any solution for this ?

     

    I have to do mac authentication with profiling and when the device is categorised as Access Point then assign correct VLANs.

     

    Thanks

     

    Vaclav



  • 2.  RE: ClearPass and iAP - mac-auth with multiple VLAN enforcement

    Posted Mar 25, 2019 12:26 PM

    Hi,

    maybe my problem has another solution and I will not need to assign multiple VLANs from ClearPass. Is it possible to set the VLANs staticaly on port (1 tagged and 1 untagged) and if the device will be profiled as Access point then assign there Allow Access enf. profile? And if not, ClearPass will send there some quarantine VLAN.

     

    Is there available anything like HPE-Port-MA-Port-Mode for Comware switches ? Or how to achieve same result ?

     

    Thanks and best regards

     

    V.

     

     



  • 3.  RE: ClearPass and iAP - mac-auth with multiple VLAN enforcement

    Posted Sep 30, 2020 07:35 AM
    Radius:IETFTunnel-Private-Group-Id=100t 200t 300u 400t 500t 600t 700t 800t

    t for tagged vlans

    u for untagged vlan



  • 4.  RE: ClearPass and iAP - mac-auth with multiple VLAN enforcement

    Posted Aug 12, 2022 07:00 PM

    hi ! 

    did you manage to achieve the port-mode on the comware 7 switch so?