Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

[Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

This thread has been viewed 37 times
  • 1.  [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    EMPLOYEE
    Posted Mar 17, 2014 03:02 AM

    Integration of Clearpass with Aerohive Introduction

     

    Much as we’d like all our customers to choose, or already have Aruba wireless, that is not always the case.   A key vendor in the marketplace is that of Aerohive, which consists of essentially fat Aps managed by a platform called HiveManager.  This tutorial outlines how to integrate Clearpass into an Aerohive wireless deployment for the purposes of corporate dot1x and guest users.

     

    Solution

     

    The following was used for this testing and demonstration.

     

    Aerohive – AP330 firmware 6.1r3

    HiveManager – Hive Manager Online 6.1r3

    Clearpass – 6.3.0.6172

     

    Assumptions – Clearpass is joined to domain and Active Directory is being used for authentication.

     

    Setup

     

    Add the Aerohive device to Clearpass as a radius client.  You will need to add each individual AP as a client or add them by subnet.

     

    1 - clearpass - add device.jpg

     

    1.1       Corporate dot1x ssid

     

    Setup your ssid with the appropriate parameters on HiveManager.

     

     2 - ssid-aerohive.jpg

     

     

    Add this ssid to your network profile, and create the Clearpass radius configuration.  Create and assign an appropriate User Profile.  In the case of this demo, we are using the same vlan as the AP for simplicity.

     

     3 - aerohive-dot1x policy.jpg

     

     

    The radius settings for Clearpass should be setup as below.

     

     3 - radius-clearpass.jpg

     

    Using the ‘802.1X Wireless’ template in Clearpass, create the service by entering the ssid and choosing the Aerohive device that was added during the setup.

     

     clearpass-corp service.jpg

     

    Add the attribute ‘Connection: SSID EQUALS <ssid>’ as above.  Optionally, you can set a ‘NAS-Identifier’ on the Aerohive AP and filter on that.

     

    1.1.1     Using Radius attributes to assign User Profiles.

     

    Similar to the Aruba concept of user-roles, Aerohive uses user-profiles to define different types of user rights.  Within the user-profile an attribute number is given and the radius response can be configured to return particular attributes so the user is placed into this user-profile.

     

    These attributes can be returned by adding an Enforcement Policy to your Profile as below.

     

     4 - clearpass user profile attributes.jpg

     

    Note:  The Tunnel-Private-Group-Id value must match the attribute-no of the user-profile on Aerohive.

     

    1.2       Guest ssid

     

    Aerohive can also be configured to use Clearpass for guest ssids.  There are two ways of doing this and both will be considered here.

     

    1.2.1     Using Aerohive portal and Clearpass as radius and Guest management.

     

    The Aerohive guest ssid can be set so that the internal portal on the Aerohive is served and the radius request is sent to Clearpass.  Clearpass has already been setup for guest account creation etc.

     

    Create the Aerohive ssid with the following parameters.

     

     5 - Aerohive - guest ssid.jpg

     

    Within the Network profile, add this ssid and create the captive portal profile and assign the Clearpass as the radius server.

     

     6 - aerohive network policy with guest.jpg

     

    The captive portal profile on Aerohive will need to be configured as such with the following

     

    • Registration Type – User
    • Captive Web Portal Auth Method – MSCHAPv2
    • Show success page after successful authentication.
    • Show failure page after unsuccessful login.

     

     7 - aerohive-cp using interal AP.jpg

     

    Using the Clearpass service template ‘Guest MAC Authentication’, create the guest service using the appropriate ssid and Aerohive as the NAS device.

     

    Note:  Guest MAC caching does not work with Aerohive, or at least I was unable to make it work.  The user will always be presented with the portal page, even if they have passed mac authentication.  If anyone knows how to make this work, please advise.  We will still use the MAC caching template though so that the mac is registered on Clearpass.

     

     

     8 - clearpass-guest service.jpg

     

     

     

    When the user connects, they are presented with the captive portal from the Aerohive AP.

     

     9 - aerohive portal internal.jpg

     

    The radius request is sent to Clearpass for authentication as shown in access tracker below.

     

     10 - clearpass access tracker with aerohive CP.jpg

     

    And the user is presented the success page.

     

    11 - aerohive-cp success page using internal AP.jpg

     

    1.2.2     Using Clearpass portal and Clearpass as radius and guest management

     

    The following outlines how to use Clearpass for the guest registration page and subsequent authentication.

     

    Configure the guest registration page in Clearpass Guest as below, with the following NAS-login settings.

     

    • Secure login – use https
    • IP address – 1.1.1.1
    • Password Encryption – No encryption (Note, we are still using https for the registration, so this is not a security concern)

     12 - clearpass-guest page using CP portal.jpg

     

    Configure the Aerohive captive portal settings as shown below.

     

    • Registration type – External authentication
    • Authentication method – CHAP
    • Login URL – address of your defined guest registration page.
    • Password Encryption – No Encryption. 
    • Enable https

    13 - aerohive-cp using CP portal.jpg 

     

    After registering using the Clearpass portal, the user is presented with the success page served from the Aerohive AP.

     

     

     11 - aerohive-cp success page using internal AP.jpg

     

     



  • 2.  RE: [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    Posted Mar 17, 2014 08:27 AM

    Spot on tutorial - Kudos yet again for an excellent summary! Rockon!



  • 3.  RE: [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    EMPLOYEE
    Posted Mar 17, 2014 10:57 AM

    Clearpass is used in many multi vendor environments. Great Tutorial!



  • 4.  RE: [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    Posted Dec 10, 2014 04:39 PM

    Do you know if you can tie captive portals to user profiles with the Hive?  i'm trying to get fancy and do redirects to onboard non-TLS devices.  This is so much easier with just Aruba gear....



  • 5.  RE: [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    EMPLOYEE
    Posted Dec 10, 2014 04:52 PM

    Unfortunately I don't think so.

     

    The captive portal is tied to the ssid, which makes things like that difficult.  It's the same with the mac caching on CPPM....I couldn't get that to work either.



  • 6.  RE: [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    Posted Dec 10, 2014 04:53 PM

    Thanks for the reply... I've reach out to a few hive guys.  If they come up with anything I'll post back here.  



  • 7.  RE: [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    Posted Feb 20, 2018 03:49 PM
    Hi,
    We use Clearpass for guest user on Aerohive AP.
    Is it possible to disconnect immediately the users on the AP when the guest users expired?
    I read about radius COA but seams to not work.
    Thanks
    Luke


  • 8.  RE: [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    EMPLOYEE
    Posted Aug 13, 2018 11:33 AM

    Aerohive seem to have added an enhancement that avoids Captive Portal redirect after successfull MAC authentication. See here: https://community.aerohive.com/aerohive/topics/avoid-device-going-through-captive-portal

     

    Seems CLI only option. In combination with external Captive Portal, the command is:

     

    security-object <string> security additional-auth-method mac-based-auth fallback-to-ecwp



  • 9.  RE: [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    EMPLOYEE
    Posted Dec 21, 2018 04:22 AM

    Thanks but I've tested and this doesn't work either :-(



  • 10.  RE: [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    Posted Jan 08, 2019 04:39 PM

    1.1.1.1 as the IP address for login doesn't work for me. I used 198.18.34.1 instead and that works to POST to /reg.php.



  • 11.  RE: [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    Posted May 07, 2019 08:01 AM

    Hi guys

    Has anyone tried to do this using AeroHive Classic? I know Clearpass, but not Aerohive..

     

    Anyways it's slightly different from the screens in this post, and ofc. I can't get that to work. I was hoping to do mac-auth with CoA instead of the old method of doing Guest redirection, but seems that's not supported.

     

     



  • 12.  RE: [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    Posted Mar 14, 2020 09:04 PM
      |   view attached

    Here is a PDF walk-through on how to configure Extreme IQ (Formerly Hivemanager NG) Guest with MAC-Caching.

     

    Tested with EIQ 8.4.r7 on an AP130 with CPPM 6.8.4. 

    *NOTE: Earlier versions of firmware seem to be hit and miss on which ones support MAC-Auth w/ Captive Portal fallback. See here 

     

     

    Attachment(s)

    pdf
    Aerohive-Guest-MAC-Cache.pdf   218 KB 1 version


  • 13.  RE: [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    Posted Aug 03, 2022 04:24 AM
    I've gotten this mostly working with XIQ but can't get CoA working. First is that the Aerohive device type just doesn't support CoA, so you have to make the APs Extreme device type. Second is my CoA packet is getting a NAK, which I haven't yet figured out why.


  • 14.  RE: [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    Posted Aug 23, 2022 12:33 AM
    Per https://community.arubanetworks.com/discussion/coa-message-doesnt-include-message-authenticator I found out you can add Message-Authenticator with a fake value and ClearPass will fill it in correctly when it sends the packet:




  • 15.  RE: [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    Posted 18 days ago

    Hi,

     

    We are setting up a hybrid ExtremCloud IQ Pilot with remote AP 305C configuration.

    We want to keep our Clearpass infrastructure to manage guests.

     

    We found a complete guide https://extremenetworks2com.sharepoint.com/sites/kcs/External/000021388/ExtremeWireless%20ClearPass%...

     

    however it specify screens that are not present on our controler site. We need to find where we could configure attributs send from an external CWP to clear pass.

    You may see on attachments :

    - in documentation.png the original doc which is talking about "attributes to send" to external cwp

    - in policy.png our policy config with external cwp selected

    - in cwp.png our external captive portal configuration

    We need to find where attribut to send have to be select.

     

    Right now, without this configuration finalized, clearpass does not receive any radius att and service is not captured.

     

    Please help,

     

    Regards,




  • 16.  RE: [Tutorial] Aerohive Integration with Clearpass - corp and guest #mhc

    EMPLOYEE
    Posted 13 days ago

    If your question is how to setup the Extreme side to send attributes, you may have better results posting in an Extreme forum or reaching out to their support.

    What the documentation describes it that your controller/AP appends the ClearPass URL with the SSID and MAC address, such that ClearPass is aware.
    Do you see the ClearPass guest page? If so what does the URL look like? Maybe the attributes are now included by default.

    This video, which shows the interactions with ClearPass and Aruba equipment may help as well to understand how it should work in your case. It should be similar to what you need to achieve, and the troubleshooting workflow may help with that.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------