Security

 View Only
  • 1.  CPPM Downloadable Roles with Application Authentication

    Posted Nov 05, 2019 03:55 PM

    CPPM 6.7.12

    I'm setting up switch DUR for a wired guest authentication scenario.

     

    1. User is initially redirected to Web Login (App Auth service)

    2. User logs in and receives DUR. (Issue here)

    3. MAC-Cache moving forward with DUR.

     

    My issue is that Application Authentication services don't allow me to select a DUR enforcement profile.

     

    Q: Is this by design? 

     

    Q2: Is the correct way to accomplish this to use a RADIUS service instead?



  • 2.  RE: CPPM Downloadable Roles with Application Authentication
    Best Answer

    Posted Nov 05, 2019 04:57 PM

    For your first question, Yes. You can't return radius profiles unless your using a radius service.

    For your second question:

    What you could do, is once the user completes the captive portal, the enforcement profiles update the endpoint with specfic attributes, and performs a CoA to reauth the user.

    Then when the reauth happens, those new attributes that were assigned will cause them to get the correct DUR.

    Whether or not that is the correct way,  I'll let someone with a little more Clearpass Knowledge answer that



  • 3.  RE: CPPM Downloadable Roles with Application Authentication

    Posted Nov 05, 2019 05:16 PM

    That was my suspicion. However, going through my ACCX lab material, all of the Guest-Wired stuff says to create an Application Service to handle the captive portal logins in conjuction with DURs. 

     

    I should have trusted my instincts.



  • 4.  RE: CPPM Downloadable Roles with Application Authentication

    Posted Nov 05, 2019 05:38 PM

    It seems the best way is to use the Wired guide that @Tim keeps up to date. 

    1. Create WebLogin page

    2. Create WebAuth service since it is server-initiated.

    3. Update endpoint with MAC Caching attributes.

    4. MAC-Auth service to honor the set attributes, apply DUR.

     

    Training folks just need to update the guides.

    Thanks for the clarification, though.

     



  • 5.  RE: CPPM Downloadable Roles with Application Authentication

    Posted Aug 27, 2025 04:51 PM
    Hello, community.
     
    We are studying the possibility of configuring a ClearPass workflow for users trying to connect to SSID X but who do not yet have the OnGuard Agent installed.
     
    The idea would be as follows:
     
    The user connects to SSID X.
     
    ClearPass detects that the device does not have the Agent installed.
     
    The user is automatically redirected to a portal page, where the link to download and install the OnGuard Agent would be available.
     
    Is there a native way in ClearPass to configure this automatic download portal?
     
    Should this be done via a captive portal integrated with the posture service (Posture/OnGuard), or is there another recommended best practice?
     
    Has anyone in the community implemented this scenario and could share their experience or best practices?
    -------------------------------------------