Security

 View Only
last person joined: 15 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass - dynamic form

This thread has been viewed 16 times
  • 1.  ClearPass - dynamic form

    Posted Mar 23, 2023 06:56 AM

    Hi all experts,

    our customer wants to use "Create Multiple Accounts" form to create 2 types of accounts with different field options:
    1. Guest account - maximum num of accounts: 10, Expire - today 23:59, Role - Guest
    2. External Employee account - maximum num of accounts: 1, Expire - 180d, Role - Employee, email notification of expiration
    They want to have there selector field (1 | Guest, 2| External) and the rest of the fields will be predefined for these account types. Can I insert some conditions to the form where I define:
    If account type is Guest then set max num_account field to 10, set role id to Guest and expire field to today 23:59.
    Is it possible to do this?
    Thanks

    Vaclav



  • 2.  RE: ClearPass - dynamic form

    Posted Mar 29, 2023 03:42 AM

    Hi,

    I'm thinking about possible solutions and I tried to define two different multiple_users forms to one Operator but it is not possible I think. I created 2 multiple_users forms and one associate with Create Multiple Guest Accounts and sedont associate/replace with Create Guest Account. 

    If anyone has any idea how to solve this, I'd be  grateful.

    Thanks

    V.




  • 3.  RE: ClearPass - dynamic form

    EMPLOYEE
    Posted Mar 29, 2023 10:27 AM

    Are these operator created accounts? As the number of employee accounts is 1, you could use the 'Create Account' for the employee account and the 'Create Multiple' for the guest accounts; and have the different roles/expiration tied to that. Normally you either give the operator access to one specific account type, or you allow the operator to set one or more parameters like the role and expiration. You may also leverage different roles for this, for example if the user can sign in with the AD username and the e-mail address; but that may make things too complex.

    As this is also something that you probably would need to build to find out the correct way of doing it, unless someone already built the exact same thing, there may be some significant effort involved. Your Aruba Partner or Aruba Support may be able to do that with you.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 4.  RE: ClearPass - dynamic form

    Posted Mar 29, 2023 10:49 AM

    Hi Herman,

    Thanks for reply. Operator is employee and signing in with AD credentials. It is working well. And customer need to have the accounts creation process as simple as it can be. So thats why they want to use multiple_account forms, because there can be the username and passwork automatically generated. Ideally, the operator selects the type of account (Guest/External) and number of accounts (Guest: max 10 / External: max 1) and click generate button.

    And this is my problem, how to get him to choose type of account with different parameters/multiple_accounts forms.

    V.




  • 5.  RE: ClearPass - dynamic form

    MVP
    Posted Mar 30, 2023 07:52 AM

    If they are connected using Aruba wireless, it is possible to use the REST API with your own custom portal pages from your web server.

    We are using the REST API for our Guest portals currently Our solution is specific to Aruba wireless captive portal profiles though. PM me if you want more details..



    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------