Wireless Access

 View Only

Local [Internet] Egress Guest Wireless using ClearPass Captive Portal

This thread has been viewed 3 times
  • 1.  Local [Internet] Egress Guest Wireless using ClearPass Captive Portal

    Posted May 14, 2020 06:13 PM
      |   view attached

    I thought this tutorial on how to implement local egress Guest wireless with Clearpass Guest might be useful to others.  I have fought this problem and even worked with the TAC to solve the dilemma of how to use Clearpass to authorize guests while placing authorized users on a local internet circuit.   Best I (and the TAC) could come up with was to implement an additional controller to handle guest.  Since this would add cost and complexity to my projects, I continued to noodle on it in my home lab.

     

    Theobromine_0-1589493784629.png

    After some time I figured out that the best solution was to allow the default gateway for the controller be the DHCP assigned internet gateway and put routes in to send the controller's management traffic out the management interface.  Once that was done, NATing of the captive portal and DNS traffic operated correctly.

     

    This is written in the style of Aruba VRDs.  It has moved out of my lab and is currently implemented by my employer at multiple sites.

     

    Enjoy

    Attachment(s)

    pdf
    local_egress_guest.pdf   1.82 MB 1 version