YOu will need the following created in the Instant Cluster...
Authentication Server created for Captive Portal - This will contain the URL for the Webpage you want the client to land on after EAP-TLS is complete.
Need a role with Access Rules - NOte the name of this role - Something like ACME-Guest-Logon
- 1st Rule - Enforce Captive Portal
- 2nd Rule - Allow DNS
- 3rd Rule - Allow DHCP
- Next set of rules - Allow only HTTP/HTTPS to the IP of Clearpass - Create a rule for each Clearpass server
Do not attempt to switch VLANs during enforcement. That gets ugly.
In Clearpass, create an Enforcement Profile for Aruba User Role and set the Value to ACME-Guest-Logon
COnfigure the EAP-TLS Service / Enforcement policy to send the new Enforcement Profile when EAP-TLS has been completed successfully.
Test
YOur users should not be re-directed to the Captive Portal after EAP-TLS
I would be sure to test your Captive Portal functionality without EAP-TLS in play first to make sure it functions OK. To test that Certificates are correct, the re-direct works, DNS, etc. Once you confirm it is good, THEN attempt the EAP-TLS stuff above.
------------------------------
Philip Wightman, ACEX (AMFX) #69. Aruba Partner Ambassador
------------------------------