Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Guest Self-Registration Using AD Credentials

This thread has been viewed 39 times
  • 1.  ClearPass Guest Self-Registration Using AD Credentials

    Posted Jul 04, 2022 05:55 AM
    Hi Experts,

    Deeply appreciate if you guys can point me in the right direction. I have been searching online but simply cannot find a solution.

    What I want to achieve is, instead of being presented with the usual default fields for Guest User self-registration:

    The user (employee in this instance) is prompted to use his/her AD credentials to login to the Guest User Self-Registration page instead:

    And upon successful login, the "guest user" is created automatically in the Guest User database along with the Guest Device info upon clicking on the "Create" button:
    Thanks!


  • 2.  RE: ClearPass Guest Self-Registration Using AD Credentials

    Posted Jul 05, 2022 01:46 AM
    Hi Jackgarnell,

    You can create the guest service with authentication source as Guest user and AD repository  and kindly give network login page URL on WLC side for redirection.

    Thanks
    Nilesh


  • 3.  RE: ClearPass Guest Self-Registration Using AD Credentials

    Posted Jul 05, 2022 04:50 AM
    Thanks Nilesh, I know how to create the services on the CPPM side but how do I change the fields on the Guest side to AD username & password? The username & password fields for the Guest self-registration page seem to look for local credentials from the Guest DB.


  • 4.  RE: ClearPass Guest Self-Registration Using AD Credentials

    Posted Jul 05, 2022 07:56 AM
    You need to add AD as an authentication source in the service that handles the web login for the captive portal.


  • 5.  RE: ClearPass Guest Self-Registration Using AD Credentials

    Posted Jul 05, 2022 11:30 PM
    Sorry but adding AD as an authentication source does not change the fields to "Username" & "Password" for the Guest Self-Registration Page:

    1) Created a "Test" Self-Registration page with just the defaults & only the following value changed:

    2) Created using Service Templates - Guest Access - Web Login:

    3) AD added as Authentication Source:

    4) Default Roles assigned:

    5) Default Enforcement Policy allowing logins only during weekdays:

    6) Default fields still shown (Your Name, Email Address, Confirm) in Self-Registration page; does not change to "Username" & "Password" to authenticate using AD credentials:
    Any other advice is appreciated. Thanks!



  • 6.  RE: ClearPass Guest Self-Registration Using AD Credentials

    Posted Jul 05, 2022 11:45 PM
    Hi Jackgarnell,

    Your using Self registration page. How you will see the network login page,you will only see the registration page.

    If you want to login with AD crediantials just click on already have an account?sign in 
    then try logging with AD crediantials.You will be able to login if you have service with AD source.


    Thanks
    Nilesh 



  • 7.  RE: ClearPass Guest Self-Registration Using AD Credentials

    Posted Jul 06, 2022 12:27 AM
    Hi Nilesh,

    That's the problem. From this Youtube video (Aruba ClearPass Onboarding using Device Registration - YouTube), the user performed the following:

    1) Connected to SSID & entered AD credentials for RADIUS authentication. ClearPass service checks if user / user's device is in Guest repo (MAC caching perhaps) & if it is, allows access. If not, a Device Registration role is returned.

    2) If user is assigned a Device Registration role, he/she will be redirected to a Captive Portal when attempting to surf the Internet.

    3) The Captive Portal seems like a modified version of the Guest Self-Registration page, with "Username" & "Password" fields instead of the default fields (Your Name, Email Address, Confirm).

    My query is, how this Youtuber did no.3, if you happen to know.

    Much appreciated! Thanks!​