generally first i check if the config is in sync or not. if you like the CLI then you can quickly check that on the gateways with "show switches"
as the configs are pushed it increment the config-id.
now the rules in the policies can be assigned to multiple user roles. and that is pushed not the policies .
For example I have this policy called internal-nets and the is to allow access to rfc1918 networks. i have assigned that rule to a number of user roles and one of them is "employee-test"
If my post was useful accept solution and/or give kudos.
Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
Original Message:
Sent: Jun 19, 2026 07:20 AM
From: KV-417347
Subject: CNX with tunneled captive portal to ClearPass
I have my user roles applied to a Site Collection, and they are visible on the Mobility Gateways..
I mean what I don't see is the actual name of the security policy that I create, I only see a summary of all RULES under the role rights.
The system automatically creates an access-list named: sys_policy_user (for user-role name "user"), and all rules fall under this access-list name:
sys_policy_user
---------------
Priority Source Destination Service Application Action TimeRange Log Expired Queue TOS 8021P Denylist Mirror DisScan IPv4/6 Contract Mark Description
-------- ------ ----------- ------- ----------- ------ --------- --- ------- ----- --- ----- -------- ------ ------- ------ -------- ---- -----------
1 any any any permit Low 4
2 any any any-v6 permit Low 6
Even tho in CNX these 2 specific rules fall under a policy I named "allow-any". In the Mobility Gateway you only see these rules under the automatically generated access-list: "sys_policy_user".
I find this a bit confusing.
Original Message:
Sent: Jun 19, 2026 07:13 AM
From: AP-e172d8
Subject: CNX with tunneled captive portal to ClearPass
for the user role to be visible in the gateways, they need to be assigned to the device-group that the gateways are in.
------------------------------
If my post was useful accept solution and/or give kudos.
Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
------------------------------
Original Message:
Sent: Jun 19, 2026 03:47 AM
From: KV-417347
Subject: CNX with tunneled captive portal to ClearPass
Hello,
In the meanwhile we have figured it out somewhat.
It turns out that the policy rule NAME you create in Central, is NOT going to be visible on the Mobility Gateway.
However, the rule itself ("any to any permit") IS visible under the role where it's assigned to.
I was focussed on the name of my rule "allow-any", but that name will never appear on the gateway it seems.
It's kind of confusing, but it seems to be OK now.
The command "show access-rule" helped us in doing more tests for finding a solution so thank you for that.
Original Message:
Sent: Jun 18, 2026 08:05 PM
From: AP-e172d8
Subject: CNX with tunneled captive portal to ClearPass
Soon I'll be publishing my next technote that will cover New Central configuration for tunnel WLANs.
But in the mean time when you send the VSA use role from ClearPass, you need to ensure that user role and its associated policies is configured and assigned correctly to the device type and to the scope.
------------------------------
If my post was useful accept solution and/or give kudos.
Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
------------------------------
Original Message:
Sent: Jun 18, 2026 08:06 AM
From: KV-417347
Subject: CNX with tunneled captive portal to ClearPass
Hello,
In the meanwhile we have tried configuring a new policy and attaching it to the role, and now it does work...
The policy I initially created was named "allow-all", while the new policy is named "allow-any", this one immediately works.
Either "allow-all" is a restricted name, or there is something wrong with the creation config push. Unassigning and assigning again doesn't help, I didn't try to re-create it, I'll just stick with the "allow-any" for now.
We do see the output correctly.
I'm just wondering for other roles, which are enforced by Clearpass. We send aruba-user-role "user", we see the client getting the role "user", but when I do "show rights user" , I don't see the allow-any policy which I assigned to the role and pushed on Mobility Gateway level. Not sure what we are missing here.
Thanks for the assistance.
Kr,
Koen
Original Message:
Sent: Jun 17, 2026 08:07 PM
From: AP-e172d8
Subject: CNX with tunneled captive portal to ClearPass
Koen, if you don't see the Pre-Auth role then you need to check the audit trail to see what has gone wrong, or you can delete the role and start again. you can always share some screenshots here as well.
------------------------------
If my post was useful accept solution and/or give kudos.
Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
------------------------------
Original Message:
Sent: Jun 15, 2026 08:19 AM
From: KV-417347
Subject: CNX with tunneled captive portal to ClearPass
Hello,
We have applied the user role to both Mobility Gateway and Campus Access point as per test.
From the requested output: I don't see any access-rule named to the Pre-Auth user role we applied..
Kr,
Koen
Original Message:
Sent: Jun 13, 2026 07:51 PM
From: AP-e172d8
Subject: CNX with tunneled captive portal to ClearPass
have you assign the preauth user role to mobility access point?
also paste the output of the "show access-rule <preauth role name> from the AP.
------------------------------
If my post was useful accept solution and/or give kudos.
Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
------------------------------
Original Message:
Sent: Jun 13, 2026 04:32 AM
From: PE-40b8d0
Subject: CNX with tunneled captive portal to ClearPass
we have it at allow all, but we are not getting the CP being triggered, instead the client can just access any site.
Original Message:
Sent: Jun 13, 2026 02:26 AM
From: AP-e172d8
Subject: CNX with tunneled captive portal to ClearPass
yes it is basically the same concept you can specific specific allow list or just use allow-all.
Just like Instant APs, even if you use allow-all for your pre-auth role, it will by default only allow basic services like DHCP/DNS and allow access to the host in your captive portal URL.
I suggest try the allow-all policy for simple straight forward deployments. but the other way also should work.
anyway what does the exact policy for your pre-auth role look like?
------------------------------
If my post was useful accept solution and/or give kudos.
Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
------------------------------