Wireless Access

 View Only
  • 1.  External captive portal with SSO authentication

    Posted Dec 21, 2023 09:13 AM

    Hi all, 

    I would like to configure a SSID with an external captive portal which redirect on a SSO authentication from Ping-ID. This SSID is intented for my BYOD users. It actually works with Clearpass as a Radius server but we need to change the Clearpass server and the new one won't support the BYOD (security+cost reasons). 

    I know that my solution is possible on other technologies but it seems not possible with Aruba Central. I tried other solutions like Cloud auth but it does not respond to my needs. 

    Do you have a solution ? 

    Best regards,

    Nico



  • 2.  RE: External captive portal with SSO authentication

    Posted Dec 22, 2023 09:58 AM

    If cost is your main driver, I don't think there are free cloud services that offer such a guest/captive portal service. Captive portal may also not be the technology of choice for BYOD for usability and security reasons. Cloud Authentication and Policy probably, which is part of Aruba Central, has a better experience by onboarding/registering the BYOD device once, then have seamless connectivity afterwards. If you have Entra ID or Google Workspace as identity stored behind your Ping ID, that may be a solution.

    I would recommend that you with with your Aruba Partner to find the optimal solution that closest matches your requirements, and fits within your budget.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: External captive portal with SSO authentication

    Posted Dec 23, 2023 09:34 AM

    If you are fairly competent with routing, webservers, radius and IP tables there is a Open Source product called PacketFence  that worked very well for us for years.

    Not sure this is the right forum to discuss it, but if you have no choice PacketFence is a viable solution. You can even buy support..

    The only reason we are not still using it, is we includes NAC with our wireless RFP and we would have had to change our design from inline solution to switch based CoA.

    Clearpass really is the best commercial product out there, but you can't eat caviar on beans and rice budget.