Security

 View Only
last person joined: 2 days ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Does the OnBoard feature on ClearPass work with Aruba Instant On Access Point?

This thread has been viewed 24 times
  • 1.  Does the OnBoard feature on ClearPass work with Aruba Instant On Access Point?

    Posted 13 days ago

    Hello everyone,

    I received a request to configure the OnBoard feature on ClearPass for Wi-Fi network (Aruba Instant On Access Point).

    Does the OnBoard feature on ClearPass work with Aruba Instant On Access Point? If yes, can you share your experience?

    Thank you so much,

    PhuocHV.



  • 2.  RE: Does the OnBoard feature on ClearPass work with Aruba Instant On Access Point?

    EMPLOYEE
    Posted 13 days ago

    ClearPass, and Onboard, are relatively hardware agnostic.  As long as the WLAN supports 802.1X, a client provisioned using Onboard can work.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: Does the OnBoard feature on ClearPass work with Aruba Instant On Access Point?

    Posted 13 days ago

    Thank you for your quick response.

    Is it related to captive-portal or user-role on Wireless Controller? I checked the configuration guide and saw that it is related to the user-role in the Aruba Controller's SSID configuration, but I'm not sure if it is need for third-party controller?

    Thank you,

    PhuocHV.




  • 4.  RE: Does the OnBoard feature on ClearPass work with Aruba Instant On Access Point?

    EMPLOYEE
    Posted 13 days ago

    Onboard is a device provisioning service.  How you go about getting a user over to the Onboard interface can utilize captive portal and user roles, but isn't required.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: Does the OnBoard feature on ClearPass work with Aruba Instant On Access Point?

    Posted 12 days ago

    Thank you so much for your response.

    I am trying configure Onboard with Instant On AP15 (AP15 supported 802.1X).

    However, when device is authenticated 802.1x successfully it's not pop-up onboarding portal.

    On the Access Tracker I saw the device is getting "RADIUS Response: Aruba-User-Role is BYOD-Provision". I understand that role have to configure on Aruba Controller. But we are trying to do that with Instant On AP.

    Please support me if you have any ideas?

    Thank you so much,

    PhuocHV.




  • 6.  RE: Does the OnBoard feature on ClearPass work with Aruba Instant On Access Point?

    EMPLOYEE
    Posted 11 days ago

    I have zero experience with ION.  Assuming ION still uses user roles, the user role that you are returning to the AP would need to be configured as a captive portal enforcement with redirect to the Onboard landing page that you are using.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 7.  RE: Does the OnBoard feature on ClearPass work with Aruba Instant On Access Point?

    Posted 9 days ago

    Thank you for your response.

    I have tested on AIO AP with Android phone, it can pop-up provisioning page but after login username/password successfully to download QuickConnect so at this time the device can't access internet to download QuickConnect.

    I know that if done on Aruba Controller, we can push the role from ClearPass to Aruba Controller to the device can access the Internet and after provisioning is completed the device will receive another role.

    But for the AIO AP, it does not support user-role configuration. I can't configure any roles on this device.

    Please help me if you have any ideas!

    Thank you so much!

    PhuocHV.




  • 8.  RE: Does the OnBoard feature on ClearPass work with Aruba Instant On Access Point?

    EMPLOYEE
    Posted 8 days ago

    Ah, so no, what you are trying to do won't work since InstantON doesn't support the full user role functionality.  You'll either need to move to one of the AOS options or use a more manual process for Onboard.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 9.  RE: Does the OnBoard feature on ClearPass work with Aruba Instant On Access Point?

    Posted 8 days ago

    Can you explain more detail about "manual process for Onboard"?

    Thank you so much!

    PhuocHV.




  • 10.  RE: Does the OnBoard feature on ClearPass work with Aruba Instant On Access Point?

    EMPLOYEE
    Posted 8 days ago

    Provide a direct link to the Onboard provisioning URL.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 11.  RE: Does the OnBoard feature on ClearPass work with Aruba Instant On Access Point?

    Posted 8 days ago

    Thank you for your quick response.

    But client also need to connect SSID to access internet for download QuickConnect, correct?




  • 12.  RE: Does the OnBoard feature on ClearPass work with Aruba Instant On Access Point?

    EMPLOYEE
    Posted 7 days ago

    That's why that is a "manual" process.  Device has to have a network connection that allows all the necessary communications (a guest network, for instance) and then would have to manually initiate the Onboard flow via a browser.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 13.  RE: Does the OnBoard feature on ClearPass work with Aruba Instant On Access Point?

    MVP
    Posted 6 days ago

    One quick comment.

    ClearPass was designed for medium to large enterprise networks. Instant On was designed for small home networks.

    Aruba Instant, designed for small enterprise networks, is also somewhat supported in ClearPass;

    In my personal 15 year experience with Aruba products, you can expect some issues when trying to use a product or ceature outside its designed purposes.

    I have quite a bit of experience with ClearPass, especially with ArubaOS managed on premises. I have never used InstantOn though. You may find experiences vary depending on the ClearPass version used. We have chosen 6.12.x due to the Entra ID support in 6.12.



    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------