Hello, community.
We are studying the possibility of configuring a ClearPass workflow for users trying to connect to SSID X but who do not yet have the OnGuard Agent installed.
The idea would be as follows:
The user connects to SSID X.
ClearPass detects that the device does not have the Agent installed.
The user is automatically redirected to a portal page, where the link to download and install the OnGuard Agent would be available.
Is there a native way in ClearPass to configure this automatic download portal?
Should this be done via a captive portal integrated with the posture service (Posture/OnGuard), or is there another recommended best practice?
Has anyone in the community implemented this scenario and could share their experience or best practices?
-------------------------------------------
Original Message:
Sent: Nov 05, 2019 03:54 PM
From: zemerick1
Subject: CPPM Downloadable Roles with Application Authentication
CPPM 6.7.12
I'm setting up switch DUR for a wired guest authentication scenario.
1. User is initially redirected to Web Login (App Auth service)
2. User logs in and receives DUR. (Issue here)
3. MAC-Cache moving forward with DUR.
My issue is that Application Authentication services don't allow me to select a DUR enforcement profile.
Q: Is this by design?
Q2: Is the correct way to accomplish this to use a RADIUS service instead?