Security

 View Only
  • 1.  Clearpass Zone DMZ or LAN

    Posted Jul 08, 2026 10:38 AM

    Hi,

    We are planning an Aruba ClearPass deployment and would appreciate your recommendations on the following design questions:

    1. We plan to place the ClearPass management interfaces and the Virtual IP (VIP) in a dedicated VLAN. According to Aruba best practices, should this VLAN be connected to the firewall's LAN zone or placed in a DMZ, considering that ClearPass will host the Guest captive portal?

    2. Is it recommended that the Publisher, Subscriber, and VIP management IP addresses reside in the same subnet, or should the VIP be placed in a separate subnet from the management interfaces?



  • 2.  RE: Clearpass Zone DMZ or LAN

    Posted Jul 08, 2026 10:56 AM
    1. We plan to place the ClearPass management interfaces and the Virtual IP (VIP) in a dedicated VLAN. According to Aruba best practices, should this VLAN be connected to the firewall's LAN zone or placed in a DMZ, considering that ClearPass will host the Guest captive portal? ClearPass is typically deployed in a DMZ or Network Services segment (RADIUS TACACS, AD, etc...) on your network. You would put the guest vlan into a MZ and control its access to the ClearPass destinations for webauth.

    2. Is it recommended that the Publisher, Subscriber, and VIP management IP addresses reside in the same subnet, or should the VIP be placed in a separate subnet from the management interfaces? They would have to be in the same subnet to be a part of the same VIP. VRRP is used for the VIP, and requires you to be on the same layer-2 VLAN. If you are deploying VMs, read the ClearPass vm install documentation (ClearPass Docs | Configuration & Integration Guides, Solution Guides, Release Notes, User Guides | Security). Subscribers can be added to the same vlan or any other subnet that has L3 reachability to the Publisher for database sync and config. If you are deploying worldwide, you would end up using Zones to control the replication traffic propagation. 



    ------------------------------
    Dustin Burns

    Lead Mobility Engineer @Worldcom Exchange, Inc.

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2022-2023
    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 3.  RE: Clearpass Zone DMZ or LAN

    Posted Jul 08, 2026 12:03 PM

    Thank you very much for the explanation.

    What is the recommended ClearPass design:

    • Management interface in the existing management VLAN (LAN zone) and data interface(DMZ Zone) in a separate guest-facing subnet?
    • Or a dedicated ClearPass management VLAN in the DMZ zone with guest traffic and no data Port?

    What should be considered when choosing between these two deployment designs?




  • 4.  RE: Clearpass Zone DMZ or LAN

    Posted Jul 08, 2026 03:42 PM

    Standard practice is just using the MGMT port unless your security policies need management traffic to exist on a separate air gaped or separate network segment for than the DATA. If you look up the routing decisions ClearPass makes while using MGMT+DATA it will make sense. Should be in the documentation I linked.



    ------------------------------
    Dustin Burns

    Lead Mobility Engineer @Worldcom Exchange, Inc.

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2022-2023
    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 5.  RE: Clearpass Zone DMZ or LAN

    Posted Jul 15, 2026 04:05 AM
    Edited by HR-abaef5 Jul 15, 2026 04:10 AM

    Please note that in most cases for security you would want only one interface. If you enable DATA+MGMT, you simply have two interfaces into the same box. If this box is in the DMZ, publicly (or semi-publicly over your guest WiFi) accessible, that would means that if someone is able to fully compromise the ClearPass server through the guest interface, and can take full control, an interface leading into your management network is a great stepping point towards the rest of your infrastructure. In my view, the only system that can have interfaces in multiple security zones (like DMZ, LAN, MGMT) in your network is a firewall. You can use it for routing, if security is the reason you probably should not. And if you connect in multiple networks make sure your security measures are similar, like using port security to prevent access to other devices in that same management network. This also applies to other products that have multiple interfaces; only few devices have truly separated management and data interfaces.

    EDIT: Not saying that ClearPass is an insecure product; it's just from my security background I learned that every software product may have vulnerabilities at some point in time. My view on separated management VLANs is more generic than ClearPass specific.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------