ClearPass Guest Access with Username only

ClearPass - Username Only Captive Portal

Reading Time: 17 minutes In the past, I saw a lot of guest workflows which either did a very overloaded username and password authentication to fully authenticate the guest or the simple “Just Accept the Ts and Cs”. The first one is very complex for the guest but gives you the option to see who is online and controls … Read more

ClearPass SSO with Google Workspace

ClearPass SSO with Google Workspace - Access Tracker Input

Reading Time: 8 minutes You can easily configure ClearPass SSO to use Google Workspace for all kinds of Single Sign On based logins. This post will show how to use Google Workspace to authenticate your ClearPass Operators and Guest admins. I have quite a similar post with Azure AD here: ClearPass SSO with Azure AD If you read the … Read more

Use ClearPass RestAPI in Enforcement Profile

Added Device in the Guest Device DB using ClearPass RestAPI

Reading Time: 6 minutes The ClearPass RestAPI is powerful and has many helpful options during authentication, e.g. sending a mail as a notification. The following post will show, how to use the ClearPass RestAPI during authentication for different tasks. In my scenario, I will create an entry in the Guest Device Repository, if the mac address is unknown and … Read more

Add Custom SQL Queries to CPPM Auth Sources

Custom Queries are not allowed

Reading Time: 3 minutes We all know the default authentication sources in ClearPass, like GuestDB or Time Source. Since some versions, it is impossible to edit or add custom SQL queries for those authentication sources. This is cumbersome and breaks some often-used scenarios. If you see the following error, you are in the situation I’m talking about: There is … Read more

Aruba Downloadable User Roles

Downloadable User Role Flow Chart

Reading Time: 16 minutes This post is all about Aruba Downloadable User Roles and how to use them for wired and wireless access with dot1x and mac authentication. If you use Downloadable User Roles, you get a central point of configuration for all access-related configurations. ClearPass, which is used as the radius server, will have all the roles available. … Read more

Aruba Stuff in EVE-NG

EVE-NG - Device ID

Reading Time: 8 minutes I discovered that EVE-NG supports a lot of Aruba Stuff and in this post, I will show how to get it running in EVE-NG. I did a first post on this with the topic on how to install EVE-NG in Azure here: https://www.flomain.de/2020/11/eve-ng-in-azure/(opens in a new tab) This was related to EVE-NG in Azure, the … Read more

Aruba AP Authentication

Campus AP Authentication - Provision AP for EAP-TLS

Reading Time: 19 minutes Most organizations are moving to a network where all ports are authenticated. This could lead to problems when we try to connect an AP to a network port as AP authentication is more than just an accept. There are two types of AP that might be considered. First, the Campus AP, which needs to connect … Read more

ClearPass Sponsored Guest Login

ClearPass Sponsored Guest Login - Guest Caching Wizard

Reading Time: 10 minutes This post describes how to set up a self-registration guest login page with sponsor approval. I use this ClearPass sponsored guest login at home for all my guests. Actually, my wife had the idea to use this kind of setup. The solution will be very easy but you will get a good overview of how … Read more

ClearPass SSO with Azure AD

ClearPass SSO with Azure AD - Setup SSO

Reading Time: 7 minutes In this post, I show how to configure ClearPass SSO with Azure AD. I use SSO (single sign-on) to authenticate operators, using ClearPass. To use SSO for users to authenticate against the network and onboard new devices, for example, will be a later post. What and Why? So what is SSO or single sign-on? Actually … Read more

ClearPass with Gmail SMTP Server

ClearPass with Gmail - Add Context Server

Reading Time: 3 minutes Most of you will use some kind of mail server to allow ClearPass sending mails. So even if you do not use ClearPass with Gmail, this might be interesting, even if the ClearPass part is the simple part of this post. If you use a Gmail account for sending emails from your ClearPass this might … Read more