Controllerless Networks

 View Only
Expand all | Collapse all

CNX with tunneled captive portal to ClearPass

This thread has been viewed 59 times
  • 1.  CNX with tunneled captive portal to ClearPass

    Posted 30 days ago

    Hi,

    We're trying to set up an captive portal to ClearPass in CNX tunneled to gateway, but we're getting stuck on the required "Assign Pre-Authentication Role". What do we enter here for policy? We've tried to base ourself on AOS8 configuration (allow DNS/DHCP/IP to CP, but it fails to work).

    The manual is not really any help on this...

    Captive Portal Authentication Profile

    Hpe remove preview
    Captive Portal Authentication Profile
    Captive portal is an authentication method supported by HPE Aruba Networking Central. Captive portal displays a web page, which requires users to either view and agree to an Acceptable Usage Policy, or enter the user ID and password. You can configure captive portal for guest users without authentication, or for registered users who must be authenticated on an external server.
    View this on Hpe >

    In classic central it was easy as "enforce captive portal" and it worked



  • 2.  RE: CNX with tunneled captive portal to ClearPass

    Posted 29 days ago

    yes it is basically the same  concept you can specific specific allow list or just use allow-all.

    Just like Instant APs, even if you use allow-all for your pre-auth role, it will by default only allow basic services like DHCP/DNS and allow access to the host in your captive portal URL. 

    I suggest try the allow-all policy for simple straight forward deployments. but the other way also should work.

    anyway what does the exact policy for your pre-auth role look like? 



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: CNX with tunneled captive portal to ClearPass

    Posted 29 days ago

    we have it at allow all, but we are not getting the CP being triggered, instead the client can just access any site.




  • 4.  RE: CNX with tunneled captive portal to ClearPass

    Posted 29 days ago

    have you assign the preauth user role to mobility access point? 

    also paste the output of the "show access-rule <preauth role name> from the AP.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 5.  RE: CNX with tunneled captive portal to ClearPass

    Posted 26 days ago

    preauth role has been assigned to Device group scope (access points and gateway), but when issuing the command, we don't see the role popping up besides the defaults.




  • 6.  RE: CNX with tunneled captive portal to ClearPass

    Posted 26 days ago

    Could you share screenshots of your configuration? Is the role configured on the gateway and your enforcing captive portal form there instead?



    ------------------------------
    Dustin Burns

    Lead Mobility Engineer @Worldcom Exchange, Inc.

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2022-2023
    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 7.  RE: CNX with tunneled captive portal to ClearPass

    Posted 26 days ago
    Edited by PE-40b8d0 26 days ago
    image
    Assigned Scopes
    Global
    Global
    Campus
    Site Collection
    grp_xxxx
    Device Group
    grp_xxxx
    Device Group

    The policy used by the role:

    image




  • 8.  RE: CNX with tunneled captive portal to ClearPass

    Posted 26 days ago

    Looks like there are two policies applied ot the role. Can you show the second one?



    ------------------------------
    Dustin Burns

    Lead Mobility Engineer @Worldcom Exchange, Inc.

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2022-2023
    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 9.  RE: CNX with tunneled captive portal to ClearPass

    Posted 26 days ago

    if you dont see the preauth role when you run  "show access-rule <preauth role name>" then that's the issue.

    Check if there are sync issues in the audit trail.

    This is from my working setup.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 10.  RE: CNX with tunneled captive portal to ClearPass

    Posted 25 days ago

    This is in the audit trail:

    Configuration settings were filtered for device ['xx:xx:xx:xx:xx:xx'] due to device capability limitations.

    Module: Policy, Profile: sys_policy_XXXtest
    Unsupported settings: Role (supported deleting configurations: non-compatibility with AP(diatype ext))

    These settings are not supported on this device type and were filtered from the device configuration.

    --

    Configuration settings were filtered for device ['xx:xx:xx:xx:xx:xx'] due to device capability limitations.

    Module: Wlan, Profile: GUESTXXX
    Unsupported settings: Local Proxy Ns

    These settings are not supported on this device type and were filtered from the device configuration.

    Role was deleted and readded, now it pushed it. We will test the portal later today




  • 11.  RE: CNX with tunneled captive portal to ClearPass

    Posted 25 days ago
    Edited by DB-280928 25 days ago

    I would return a pre-auth role that only exists on the AP. This is typically how it was handled in Classic Central, so i assume you want to do the same here. Pre-Auth role gets applied to the user at the AP level.

    In the AOS 10‑style SSID workflow, the “Pre‑authentication role” is selected under the SSID’s Access settings on the AP side (WLAN profile). That role defines what the client can hit before auth (captive portal, DNS, DHCP, etc.) and is enforced on the AP, regardless of whether the SSID is locally bridged or tunneled to a gateway. Once the user authenticates, the post‑auth role (from Central config or returned via RADIUS “Aruba-User-Role” or “Aruba-User-Vlan”) is what the gateway/controller will actually apply to the tunneled traffic. So for a tunneled guest SSID, you still set the pre‑auth role only in the WLAN/SSID config in Central; the controller does not need a separate “pre‑auth” role config, just the normal user roles and VLANs that you expect to use after auth.

    For a tunneled guest SSID in new Central:

    - On the SSID (under Access), choose a pre‑auth role like “guest-preauth” with rules permitting DNS, DHCP, portal IP/FQDN, etc……

    - On the gateway side (via Central), make sure you have the matching user roles and policies that will be used AFTER auth (e.g., `guest-internet-only`), and if needed, map them to VLANs.

    You don’t have to (and can’t, in the same way) separately “assign” that pre‑auth role on the controller for the tunneled SSID; the AP’s role assignment at association time is what matters.



    ------------------------------
    Dustin Burns

    Lead Mobility Engineer @Worldcom Exchange, Inc.

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2022-2023
    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 12.  RE: CNX with tunneled captive portal to ClearPass

    Posted 25 days ago

    Hello,

    We have applied the user role to both Mobility Gateway and Campus Access point as per test.

    From the requested output: I don't see any access-rule named to the Pre-Auth user role we applied..

    Kr,

    Koen




  • 13.  RE: CNX with tunneled captive portal to ClearPass

    Posted 25 days ago

    Koen, if you don't see the Pre-Auth role then you need to check the audit trail to see what has gone wrong, or you can delete the role and start again. you can always share some screenshots here as well.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 14.  RE: CNX with tunneled captive portal to ClearPass

    Posted 24 days ago

    Hello,

    In the meanwhile we have tried configuring a new policy and attaching it to the role, and now it does work...

    The policy I initially created was named "allow-all", while the new policy is named "allow-any", this one immediately works.

    Either "allow-all" is a restricted name, or there is something wrong with the creation config push. Unassigning and assigning again doesn't help, I didn't try to re-create it, I'll just stick with the "allow-any" for now.

    We do see the output correctly.

    I'm just wondering for other roles, which are enforced by Clearpass. We send aruba-user-role "user", we see the client getting the role "user", but when I do "show rights user" , I don't see the allow-any policy which I assigned to the role and pushed on Mobility Gateway level. Not sure what we are missing here.

    Thanks for the assistance.

    Kr,

    Koen




  • 15.  RE: CNX with tunneled captive portal to ClearPass

    Posted 24 days ago

    Soon I'll be publishing my next technote that will cover New Central configuration for tunnel WLANs.

    But in the mean time when you send the VSA use role from ClearPass, you need to ensure that user role and its associated policies is configured and assigned correctly to the device type and to the scope.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 16.  RE: CNX with tunneled captive portal to ClearPass

    Posted 23 days ago

    Hello,

    In the meanwhile we have figured it out somewhat.

    It turns out that the policy rule NAME you create in Central, is NOT going to be visible on the Mobility Gateway.

    However, the rule itself ("any to any permit") IS visible under the role where it's assigned to.

    I was focussed on the name of my rule "allow-any", but that name will never appear on the gateway it seems.

    It's kind of confusing, but it seems to be OK now.

    The command "show access-rule" helped us in doing more tests for finding a solution so thank you for that.




  • 17.  RE: CNX with tunneled captive portal to ClearPass

    Posted 23 days ago

    for the user role to be visible in the gateways, they need to be assigned to the device-group that the gateways are in.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 18.  RE: CNX with tunneled captive portal to ClearPass

    Posted 23 days ago

    I have my user roles applied to a Site Collection, and they are visible on the Mobility Gateways..

    I mean what I don't see is the actual name of the security policy that I create, I only see a summary of all RULES under the role rights.

    The system automatically creates an access-list named: sys_policy_user (for user-role name "user"), and all rules fall under this access-list name:

    sys_policy_user
    ---------------
    Priority  Source  Destination  Service  Application  Action  TimeRange  Log  Expired  Queue  TOS  8021P  Denylist  Mirror  DisScan  IPv4/6  Contract  Mark  Description
    --------  ------  -----------  -------  -----------  ------  ---------  ---  -------  -----  ---  -----  --------  ------  -------  ------  --------  ----  -----------
    1         any     any          any                   permit                           Low                                           4
    2         any     any          any-v6                permit                           Low                                           6

    Even tho in CNX these 2 specific rules fall under a policy I named "allow-any". In the Mobility Gateway you only see these rules under the automatically generated access-list: "sys_policy_user".

    I find this a bit confusing.




  • 19.  RE: CNX with tunneled captive portal to ClearPass

    Posted 23 days ago

    generally first i check if the config is in sync or not. if you like the CLI then you can quickly check that on the gateways with "show switches" 

    as the configs are pushed it increment the config-id.

    now the rules in the policies can be assigned to multiple user roles. and that is pushed not the policies . 

    For example I have this policy called internal-nets and the is to allow access to rfc1918 networks. i have assigned that rule to a number of user roles and one of them is "employee-test"

    when the config is pushed to the gateway, it is show here

    there is "sys_policy_"  prepended to the user role which is ""employee-test" 



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------