Use ClearPass RestAPI in Enforcement Profile

Added Device in the Guest Device DB using ClearPass RestAPI

Reading Time: 6 minutes The ClearPass RestAPI is powerful and has many helpful options during authentication, e.g. sending a mail as a notification. The following post will show, how to use the ClearPass RestAPI during authentication for different tasks. In my scenario, I will create an entry in the Guest Device Repository, if the mac address is unknown and … Read more

Add Custom SQL Queries to CPPM Auth Sources

Custom Queries are not allowed

Reading Time: 3 minutes We all know the default authentication sources in ClearPass, like GuestDB or Time Source. Since some versions, it is impossible to edit or add custom SQL queries for those authentication sources. This is cumbersome and breaks some often-used scenarios. If you see the following error, you are in the situation I’m talking about: There is … Read more

Welcome 2023 – Changes

Reading Time: 2 minutes The last years were quite challenging and I’m sure, this year will not change this on the short run. The Pandemic, followed by supply chain issues did not only affected our professional lives, but our personal lives as well. And while I was hoping that everything will get better in 2022, we saw this brutal … Read more

Azure Routing for EVE-NG

Azure Routing - Effective Routes

Reading Time: 4 minutes This time I write a small post about my Azure Routing for EVE-NG and how to get this working with my Azure Gateway to access nodes on the EVE-NG. In a previous post, I wrote about the IPSec tunnel from my home lab to Azure. To get access to the nodes on the EVE-NG VM … Read more

Azure Site to Site VPN with an Aruba Gateway

Aruba Gateway Site to Site VPN - Tunnel Status

Reading Time: 4 minutes As described in earlier posts I run EVE-NG in Azure. For several reasons, I need a direct connection to EVE-NG and the nodes within EVE-NG. I could use an Aruba Gateway in Azure but this would consume too much of my tight budget, so I decided to use an Azure Site to Site VPN with … Read more

Unmanaged SD-Branch Virtual Gateway in EVE-NG

Virtual Gateway - Download Device Identity

Reading Time: 3 minutes For some testing, I need some Aruba SD-Branch gateways. Instead of using hardware gateways, which I do not have, I use a virtual gateway. You could run them in ESXi as well, but why not use EVE-NG for this. For instructions on how to install EVE-NG use the following link: EVE-NG in Azure For other … Read more

Wired Guest Access with Aruba Wireless Gear

Create new Network - Security

Reading Time: 6 minutes This is maybe an uncommon scenario but I was asked to write something about this topic. Let’s assume you have Aruba Wireless Gear but your switching stuff is not from Aruba. In this post, I will show how to configure Aruba Controllers or Aruba IAPs to provide Guest Access to wired users as well. I … Read more

Aruba Downloadable User Roles

Downloadable User Role Flow Chart

Reading Time: 16 minutes This post is all about Aruba Downloadable User Roles and how to use them for wired and wireless access with dot1x and mac authentication. If you use Downloadable User Roles, you get a central point of configuration for all access-related configurations. ClearPass, which is used as the radius server, will have all the roles available. … Read more

Aruba Remote Mesh using an Aruba RAP

Aruba Remote Mesh - Topology

Reading Time: 8 minutes For an urgent project, I was asked to set up a Remote Mesh, and actually, I was thinking it is an easy task as I had created mesh networks before. But Remote Mesh is a different beast and it took me more than three days to get this working. To help others with this kind … Read more

Aruba Stuff in EVE-NG

EVE-NG - Device ID

Reading Time: 8 minutes I discovered that EVE-NG supports a lot of Aruba Stuff and in this post, I will show how to get it running in EVE-NG. I did a first post on this with the topic on how to install EVE-NG in Azure here: https://www.flomain.de/2020/11/eve-ng-in-azure/(opens in a new tab) This was related to EVE-NG in Azure, the … Read more

%d bloggers like this: