SlideShare une entreprise Scribd logo
1  sur  18
Télécharger pour lire hors ligne
 	
  
	
  
	
  
	
  
	
  
	
  
AirGroup	
  Configuration	
  How-­‐To	
  with	
  
ClearPass	
  6.0.1	
  
	
  
	
  
	
  
	
  
	
  
	
  
	
  
TechnicalNote
AirGroup Configuration How-To with ClearPass 6.0.1| February 2013
Copyright	
  
©	
  2012	
  Aruba	
  Networks,	
  Inc.	
  Aruba	
  Networks	
  trademarks	
  include	
   ,	
  Aruba	
  Networks®,	
  Aruba	
  Wireless	
  
Networks®,	
  the	
  registered	
  Aruba	
  the	
  Mobile	
  Edge	
  Company	
  logo,	
  Aruba	
  Mobility	
  Management	
  System®,	
  Mobile	
  Edge	
  
Architecture®,	
  People	
  Move.	
  Networks	
  Must	
  Follow®,	
  RFProtect®,	
  Green	
  Island®.	
  All	
  rights	
  reserved.	
  All	
  other	
  
trademarks	
  are	
  the	
  property	
  of	
  their	
  respective	
  owners	
  
Open	
  Source	
  Code	
  
Certain	
  Aruba	
  products	
  include	
  Open	
  Source	
  software	
  code	
  developed	
  by	
  third	
  parties,	
  including	
  software	
  code	
  subject	
  to	
  
the	
  GNU	
  General	
  Public	
  License	
  (GPL),	
  GNU	
  Lesser	
  General	
  Public	
  License	
  (LGPL),	
  or	
  other	
  Open	
  Source	
  Licenses.	
  Includes	
  
software	
  from	
  Litech	
  Systems	
  Design.	
  The	
  IF-­‐MAP	
  client	
  library	
  copyright	
  2011	
  Infoblox,	
  Inc.	
  All	
  rights	
  reserved.	
  This	
  
product	
  includes	
  software	
  developed	
  by	
  Lars	
  Fenneberg	
  et	
  al.	
  The	
  Open	
  Source	
  code	
  used	
  can	
  be	
  found	
  at	
  this	
  site::	
  
http://www.arubanetworks.com/open_source	
  	
  
Legal	
  Notice	
  
The	
  use	
  of	
  Aruba	
  Networks,	
  Inc.	
  switching	
  platforms	
  and	
  software,	
  by	
  all	
  individuals	
  or	
  corporations,	
  to	
  terminate	
  other	
  
vendors’	
  VPN	
  client	
  devices	
  constitutes	
  complete	
  acceptance	
  of	
  liability	
  by	
  that	
  individual	
  or	
  corporation	
  for	
  this	
  action	
  
and	
  indemnifies,	
  in	
  full,	
  Aruba	
  Networks,	
  Inc.	
  from	
  any	
  and	
  all	
  legal	
  actions	
  that	
  might	
  be	
  taken	
  against	
  it	
  with	
  respect	
  to	
  
infringement	
  of	
  copyright	
  on	
  behalf	
  of	
  those	
  vendors.	
  
Warranty	
  
This	
  hardware	
  product	
  is	
  protected	
  by	
  the	
  standard	
  Aruba	
  warranty	
  of	
  one	
  year	
  parts/labor.	
  For	
  more	
  information,	
  refer	
  
to	
  the	
  ARUBACARE	
  SERVICE	
  AND	
  SUPPORT	
  TERMS	
  AND	
  CONDITIONS.	
  
Altering	
  this	
  device	
  (such	
  as	
  painting	
  it)	
  voids	
  the	
  warranty.	
  
	
  
	
  
	
  
	
  
	
  
www.arubanetworks.com	
  
1344	
  Crossman	
  Avenue	
  
Sunnyvale,	
  California	
  	
  94089	
  
Phone:	
  408.227.4500	
  
Fax	
  408.227.4550
AirGroup Configuration How-To with ClearPass 6.0.1 | 3
Contents	
  
	
  
	
  
	
  
	
  
	
  
	
  
Audience	
  ...........................................................................................................................................................................................................	
  7	
  
Typographic	
  Conventions	
  .........................................................................................................................................................................	
  7	
  
Contacting	
  Support	
  ......................................................................................................................................................................................	
  8	
  
1.	
   AirGroup	
  Configuration	
  How-­‐to	
  with	
  ClearPass	
  6.0.1	
  ..............................................................................................	
  9	
  
Assumptions:	
  ..................................................................................................................................................................................................	
  9	
  
Step	
  1:	
   Controller	
  Configuration	
  ......................................................................................................................................................	
  9	
  
Step	
  2:	
   ClearPass	
  Setup	
  ......................................................................................................................................................................	
  11	
  
Testing	
  .............................................................................................................................................................................................................	
  17	
  
Troubleshooting	
  .........................................................................................................................................................................................	
  18	
  
	
  
	
   	
  
4 | AirGroup Configuration How-To with ClearPass 6.0.1
	
   	
  
AirGroup Configuration How-To with ClearPass 6.0.1 | 5
Figures	
  
	
  
	
  
	
  
	
  
	
  
	
  
	
  
	
  
Figure	
  1	
  Configuring	
  a	
  UDP	
  port	
  for	
  AirGroup’s	
  RFC	
  3576	
  .......................................................................................................	
  10	
  
Figure	
  3	
  Airgroup	
  AAA	
  profile	
  RFC	
  3576	
  server	
  ............................................................................................................................	
  11	
  
Figure	
  4	
  Configure	
  AirGroup	
  Services	
  ................................................................................................................................................	
  11	
  
Figure	
  5	
  Add	
  a	
  new	
  controller	
  for	
  AirGroup	
  Services	
  ..................................................................................................................	
  12	
  
Figure	
  6	
  Configure	
  AirGroup	
  Services	
  controller	
  settings	
  .........................................................................................................	
  12	
  
Figure	
  8	
  Adding	
  a	
  new	
  Local	
  User	
  in	
  CPPM	
  ......................................................................................................................................	
  13	
  
Figure	
  9	
  Create	
  an	
  AirGroup	
  Administrator	
  .....................................................................................................................................	
  14	
  
Figure	
  10	
  Create	
  an	
  AirGroup	
  Operator	
  .............................................................................................................................................	
  14	
  
Figure	
  11	
  Local	
  Users	
  GUI	
  screen	
  .........................................................................................................................................................	
  15	
  
Figure	
  12	
  Create	
  a	
  device	
  .........................................................................................................................................................................	
  15	
  
Figure	
  13	
  Register	
  Shared	
  Device	
  .........................................................................................................................................................	
  16	
  
	
   	
  
	
  
6 | AirGroup Configuration How-To with ClearPass 6.0.1
	
   	
  
AirGroup Configuration How-To with ClearPass 6.0.1 | 7
Preface	
  
	
  
	
  
	
  
	
  
	
  
Audience	
  
This	
  AirGroup	
  Configuration	
  How-­‐To	
  with	
  ClearPass	
  6.0.1	
  is	
  intended	
  for	
  system	
  administrators	
  and	
  people	
  
who	
  are	
  setting	
  up	
  AirGroup	
  configuration	
  with	
  ClearPass	
  6.0.1.	
  
Typographic	
  Conventions	
  
The	
  following	
  conventions	
  are	
  used	
  throughout	
  this	
  manual	
  to	
  emphasize	
  important	
  concepts.	
  
Type Style Description
Italics Used to emphasize important items and for the titles of books.
Boldface Used to highlight navigation in procedures and to emphasize command names and
parameter options when mentioned in text.
Sample template
code or HTML text
Code samples are shown in a fixed-width font
<angle brackets> When used in examples or command syntax, text within angle brackets
represents items you should replace with information appropriate to your
specific situation. For example:
ping <ipaddr>
In this example, you would type “ping” at the system prompt exactly as shown,
followed by the IP address of the system to which ICMP echo packets are to be sent.
Do not type the angle brackets.
	
  
	
  
	
  
8 | AirGroup Configuration How-To with ClearPass 6.0.1
Contacting	
  Support	
  
Main	
  Site	
   arubanetworks.com	
  
Support	
  Site	
   support.arubanetworks.com	
  
Airheads	
  Social	
  Forums	
  and	
  Knowledge	
  
Base	
  and	
  Knowledge	
  Base	
  	
  
community.arubanetworks.com	
  
North	
  American	
  Telephone	
   1-­‐800-­‐943-­‐4526	
  (Toll	
  Free)	
  	
  
1-­‐408-­‐754-­‐1200	
  
International	
  Telephones	
   http://www.arubanetworks.com/support-­‐services/aruba-­‐
support-­‐program/contact-­‐support/	
  
Software	
  Licensing	
  Site	
   https://licensing.arubanetworks.com/	
  
End	
  of	
  Support	
  information	
   www.arubanetworks.com/support-­‐services/end-­‐of-­‐life-­‐
products/end-­‐of-­‐life-­‐policy/	
  
Wireless	
  Security	
  Incident	
  Response	
  
Team	
  (WSIRT)	
  
http://www.arubanetworks.com/support-­‐services/security-­‐
bulletins/	
  
Support	
  Email	
  Addresses	
   	
  
Americas	
  and	
  APAC	
   support@arubanetworks.com	
  
EMEA	
   emea_support@arubanetworks.com	
  
WSIRT	
  Email	
  
Please	
  email	
  details	
  of	
  any	
  security	
  
problem	
  found	
  in	
  an	
  Aruba	
  product.	
  
wsirt@arubanetworks.com	
  
	
  
	
   	
  
AirGroup Configuration How-To with ClearPass 6.0.1 | 9
	
  
	
  
	
  
	
  
	
  
	
  
1. AirGroup	
  Configuration	
  How-­‐to	
  with	
  ClearPass	
  
6.0.1	
  
The	
  purpose	
  of	
  this	
  document	
  is	
  to	
  walk	
  through	
  how-­‐to	
  setup	
  AirGroup	
  configuration	
  with	
  ClearPass	
  6.0.1.	
  
This	
  document	
  will	
  use	
  the	
  Integrated	
  Deployment	
  Model.	
  
Assumptions:	
  
1. Controller	
  is	
  running	
  the	
  latest	
  AirGroup	
  AOS	
  Technology	
  Release	
  (at	
  the	
  time	
  of	
  this	
  document	
  it	
  
was	
  6.1.3.4-­‐Airgroup).	
  
2. ClearPass	
  6.0.1	
  non-­‐Beta	
  version	
  is	
  installed.	
  
3. IPv6	
  is	
  disabled	
  on	
  the	
  controller	
  (command:	
  no ipv6 enable).	
  
4. Aruba	
  Wireless	
  and	
  ClearPass	
  6	
  Integration	
  Guide	
  setup	
  has	
  already	
  been	
  completed.	
  
5. An	
  SSID	
  with	
  a	
  PSK	
  is	
  setup	
  for	
  testing.	
  
6. An	
  up-­‐to-­‐date	
  AppleTV	
  is	
  available	
  for	
  testing.	
  
7. An	
  Apple	
  computer	
  running	
  Mountain	
  Lion	
  (10.8.2)	
  or	
  an	
  iOS	
  device	
  running	
  iOS	
  6	
  is	
  available	
  for	
  
testing.	
  
Step	
  1: Controller	
  Configuration	
  
Use	
  SSH	
  to	
  login	
  to	
  the	
  controller	
  and	
  run	
  the	
  following	
  command	
  in	
  configure	
  terminal	
  mode:	
  
airgroup enable
firewall cp permit proto 17 ports 21234 21234
In	
  the	
  controller	
  GUI,	
  navigate	
  to	
  Configuration-­‐>Advanced	
  Services-­‐>All	
  Profiles.	
  Expand	
  Other	
  Profiles.	
  
Click	
  on	
  Airgroup	
  AAA	
  profile.	
  You	
  must	
  configure	
  a	
  UDP	
  port	
  for	
  AirGroup’s	
  RFC	
  3576.	
  You	
  cannot	
  use	
  the	
  
default	
  3799.	
  In	
  the	
  sample	
  below,	
  UDP	
  port	
  21234	
  is	
  used.	
  Enter	
  the	
  port	
  number	
  in	
  the	
  ‘Configure	
  UDP	
  port	
  
to	
  receive	
  RFC	
  3576	
  server	
  requests’	
  field	
  and	
  click	
  Apply.	
  
10 | AirGroup Configuration How-To with ClearPass 6.0.1
Figure	
  1	
  Configuring	
  a	
  UDP	
  port	
  for	
  AirGroup’s	
  RFC	
  3576	
  
	
  
Click	
  on	
  Server	
  Group	
  under	
  Airgroup	
  AAA	
  profile.	
  Select	
  the	
  ClearPass	
  6	
  server	
  group	
  that	
  was	
  created	
  in	
  
the	
  Aruba	
  Wireless	
  and	
  ClearPass	
  6	
  Integration	
  Guide.	
  
Figure	
  2	
  ClearPass	
  6	
  server	
  group	
  previously	
  created	
  
	
  
Click	
  Apply.	
  	
  
Click	
  on	
  RFC	
  3576	
  server	
  under	
  Airgroup	
  AAA	
  profile.	
  
AirGroup Configuration How-To with ClearPass 6.0.1 | 11
Figure	
  3	
  Airgroup	
  AAA	
  profile	
  RFC	
  3576	
  server	
  
	
  
Again,	
  use	
  the	
  RFC	
  3576	
  server	
  that	
  points	
  to	
  ClearPass	
  6	
  which	
  was	
  created	
  in	
  the	
  previous	
  setup	
  guide.	
  	
  
Click	
  Apply.	
  
Step	
  2: ClearPass	
  Setup	
  
Open	
  up	
  ClearPass	
  Guest	
  and	
  navigate	
  to	
  Administration-­‐>AirGroup	
  Services.	
  Click	
  ‘Configure	
  AirGroup	
  
Services’.	
  
Figure	
  4	
  Configure	
  AirGroup	
  Services	
  
	
  
Click	
  ‘Add	
  a	
  new	
  controller’.	
  	
  
12 | AirGroup Configuration How-To with ClearPass 6.0.1
Figure	
  5	
  Add	
  a	
  new	
  controller	
  for	
  AirGroup	
  Services	
  
	
  
Enter	
  the	
  appropriate	
  information.	
  	
  
Note:	
  The	
  port	
  used	
  in	
  these	
  setup	
  instructions	
  is	
  21234	
  and	
  the	
  shared	
  secret	
  was	
  configured	
  in	
  the	
  previous	
  
setup	
  guide	
  (where	
  aruba123	
  was	
  used	
  as	
  an	
  example).	
  
Figure	
  6	
  Configure	
  AirGroup	
  Services	
  controller	
  settings	
  
	
  
Click	
  Save	
  Configuration.	
  
In	
  order	
  to	
  demonstrate	
  AirGroup,	
  either	
  an	
  AirGroup	
  Administrator	
  or	
  AirGroup	
  Operator	
  account	
  must	
  be	
  
created.	
  Go	
  to	
  the	
  ClearPass	
  Policy	
  Manager	
  GUI,	
  and	
  navigate	
  to	
  Configuration-­‐>Identity-­‐>Local	
  Users.	
  	
  
AirGroup Configuration How-To with ClearPass 6.0.1 | 13
Figure	
  7	
  Configuration	
  -­‐>Identity-­‐>Local	
  Users	
  selection	
  
	
  
Click	
  Add	
  User.	
  	
  
Figure	
  8	
  Adding	
  a	
  new	
  Local	
  User	
  in	
  CPPM	
  
	
  
Create	
  an	
  AirGroup	
  Administrator:	
  
14 | AirGroup Configuration How-To with ClearPass 6.0.1
Figure	
  9	
  Create	
  an	
  AirGroup	
  Administrator	
  
	
  
In	
  this	
  example,	
  as	
  in	
  past	
  documentation,	
  the	
  password	
  used	
  is	
  test123.	
  Click	
  Add.	
  	
  
Now	
  click	
  Add	
  User,	
  and	
  create	
  an	
  AirGroup	
  Operator:	
  
Figure	
  10	
  Create	
  an	
  AirGroup	
  Operator	
  
	
  
Click	
  Add	
  to	
  save	
  the	
  ‘AirGroup	
  Operator’	
  login.	
  
The	
  ‘AirGroup	
  Administrator’	
  and	
  ‘AirGroup	
  Operator’	
  IDs	
  will	
  be	
  displayed	
  in	
  the	
  Local	
  Users	
  GUI	
  screen.	
  
AirGroup Configuration How-To with ClearPass 6.0.1 | 15
Figure	
  11	
  Local	
  Users	
  GUI	
  screen	
  
	
  
Navigate	
  to	
  the	
  ClearPass	
  Guest	
  GUI	
  and	
  click	
  the	
  Logout	
  button	
  so	
  that	
  you	
  are	
  presented	
  with	
  the	
  ClearPass	
  
Guest	
  Login	
  page.	
  Enter	
  the	
  airgroup-­‐admin	
  login	
  and	
  password.	
  	
  
Click	
  on	
  Create	
  Device.	
  	
  
Figure	
  12	
  Create	
  a	
  device	
  
	
  
The	
  following	
  page	
  is	
  displayed:	
  
16 | AirGroup Configuration How-To with ClearPass 6.0.1
Figure	
  13	
  Register	
  Shared	
  Device	
  
	
  
For	
  testing	
  purposes,	
  add	
  your	
  test	
  AppleTV	
  device	
  name	
  and	
  MAC	
  address;	
  but	
  leave	
  the	
  other	
  fields	
  blank.	
  	
  
Click	
  Register	
  Shared	
  Device.	
  
	
  
AirGroup Configuration How-To with ClearPass 6.0.1 | 17
Testing	
  
Disconnect	
  your	
  AppleTV	
  and	
  OSX	
  Mountain	
  Lion/iOS	
  6	
  devices	
  if	
  they	
  were	
  previously	
  connected	
  to	
  the	
  
wireless	
  network.	
  Remove	
  their	
  entries	
  from	
  the	
  controller’s	
  user	
  table	
  as	
  follows:	
  
Find	
  the	
  MAC	
  address	
  
“show user table”
Delete	
  them	
  from	
  the	
  table	
  
“aaa user delete mac 00:aa:22:bb:33:cc”
Reconnect	
  both	
  devices.	
  You	
  should	
  be	
  able	
  to	
  connect	
  to	
  the	
  AppleTV	
  from	
  the	
  other	
  device.	
  In	
  order	
  to	
  limit	
  
access	
  to	
  the	
  AppleTV,	
  open	
  up	
  the	
  ClearPass	
  Guest	
  GUI,	
  logging	
  in	
  as	
  the	
  user	
  that	
  created	
  the	
  device	
  
(airgroup-­‐admin	
  or	
  airgroup-­‐oper	
  were	
  the	
  example	
  usernames	
  in	
  this	
  document)	
  and	
  navigate	
  to	
  List	
  
Devices.	
  Click	
  on	
  the	
  test	
  AppleTV.	
  Click	
  Edit.	
  Now	
  add	
  a	
  username	
  to	
  the	
  Shared	
  With	
  field	
  that	
  is	
  not	
  the	
  
username	
  being	
  used	
  to	
  login	
  with	
  the	
  OSX	
  Mountain	
  Lion/iOS	
  6	
  device.	
  	
  
Disconnect	
  and	
  remove	
  the	
  OSX	
  Mountain	
  Lion/iOS	
  6	
  device	
  from	
  the	
  controller’s	
  user	
  table.	
  Reconnect	
  the	
  
device,	
  again	
  not	
  using	
  the	
  username	
  that	
  you	
  added	
  to	
  the	
  Shared	
  With	
  field.	
  The	
  AppleTV	
  should	
  not	
  be	
  
available	
  to	
  this	
  device.	
  
Disconnect	
  the	
  OSX	
  Mountain	
  Lion/iOS	
  6	
  device	
  and	
  delete	
  it	
  from	
  the	
  controller’s	
  user	
  table.	
  Reconnect	
  
using	
  the	
  username	
  that	
  was	
  added	
  to	
  the	
  Shared	
  With	
  field.	
  The	
  OSX	
  Mountain	
  Lion/iOS	
  6	
  device	
  should	
  
once	
  again	
  have	
  access	
  to	
  the	
  AppleTV.	
  
	
   	
  
18 | AirGroup Configuration How-To with ClearPass 6.0.1
Troubleshooting	
  
Problem:	
  
	
   Limiting	
  devices	
  has	
  no	
  affect.	
  
Solution:	
  
	
   Make	
  sure	
  that	
  IPv6	
  is	
  disabled.	
  
Problem:	
  
	
   OSX	
  Laptop	
  running	
  Mountain	
  Lion	
  can	
  AirPlay	
  to	
  the	
  AppleTV,	
  but	
  iOS	
  devices	
  cannot.	
  
Solution:	
  
	
   Make	
  sure	
  that	
  IPv6	
  is	
  disabled.	
  
	
  
	
  

Contenu connexe

Tendances

Tendances (20)

EMEA Airheads - What does AirMatch do differently?v2
 EMEA Airheads - What does AirMatch do differently?v2 EMEA Airheads - What does AirMatch do differently?v2
EMEA Airheads - What does AirMatch do differently?v2
 
EMEA Airheads- ArubaOS - Rogue AP troubleshooting
EMEA Airheads- ArubaOS - Rogue AP troubleshootingEMEA Airheads- ArubaOS - Rogue AP troubleshooting
EMEA Airheads- ArubaOS - Rogue AP troubleshooting
 
Managing and Optimizing RF Spectrum for Aruba WLANs
Managing and Optimizing RF Spectrum for Aruba WLANsManaging and Optimizing RF Spectrum for Aruba WLANs
Managing and Optimizing RF Spectrum for Aruba WLANs
 
Base Designs Lab Setup for Validated Reference Design
Base Designs Lab Setup for Validated Reference DesignBase Designs Lab Setup for Validated Reference Design
Base Designs Lab Setup for Validated Reference Design
 
Aruba WLANs 101 and design fundamentals
Aruba WLANs 101 and design fundamentalsAruba WLANs 101 and design fundamentals
Aruba WLANs 101 and design fundamentals
 
WLAN Design for Location, Voice & Video
WLAN Design for Location, Voice & VideoWLAN Design for Location, Voice & Video
WLAN Design for Location, Voice & Video
 
Airheads Tech Talks: Advanced Clustering in AOS 8.x
Airheads Tech Talks: Advanced Clustering in AOS 8.xAirheads Tech Talks: Advanced Clustering in AOS 8.x
Airheads Tech Talks: Advanced Clustering in AOS 8.x
 
Advanced rf troubleshooting_peter lane
Advanced rf troubleshooting_peter laneAdvanced rf troubleshooting_peter lane
Advanced rf troubleshooting_peter lane
 
Aruba 802.11n Networks Validated Reference Design
Aruba 802.11n Networks Validated Reference DesignAruba 802.11n Networks Validated Reference Design
Aruba 802.11n Networks Validated Reference Design
 
EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...
EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...
EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...
 
Aruba Mobility Controllers
Aruba Mobility ControllersAruba Mobility Controllers
Aruba Mobility Controllers
 
Campus Redundancy Models
Campus Redundancy ModelsCampus Redundancy Models
Campus Redundancy Models
 
EMEA Airheads- ArubaOS - Cluster Manager
EMEA Airheads- ArubaOS - Cluster ManagerEMEA Airheads- ArubaOS - Cluster Manager
EMEA Airheads- ArubaOS - Cluster Manager
 
Air group tb 080112_final
Air group tb 080112_finalAir group tb 080112_final
Air group tb 080112_final
 
Real-world 802.1X Deployment Challenges
Real-world 802.1X Deployment ChallengesReal-world 802.1X Deployment Challenges
Real-world 802.1X Deployment Challenges
 
Large scale, distributed access management deployment with aruba clear pass
Large scale, distributed access management deployment with aruba clear passLarge scale, distributed access management deployment with aruba clear pass
Large scale, distributed access management deployment with aruba clear pass
 
EMEA Airheads- Troubleshooting 802.1x issues
EMEA Airheads- Troubleshooting 802.1x issuesEMEA Airheads- Troubleshooting 802.1x issues
EMEA Airheads- Troubleshooting 802.1x issues
 
Network Rightsizing Best Practices Guide
Network Rightsizing Best Practices GuideNetwork Rightsizing Best Practices Guide
Network Rightsizing Best Practices Guide
 
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba CentralAirheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
 
Campus Network Design version 8
Campus Network Design version 8Campus Network Design version 8
Campus Network Design version 8
 

En vedette

8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...
Aruba, a Hewlett Packard Enterprise company
 

En vedette (20)

Aruba mobility access switch useful commands v2
Aruba mobility access switch useful commands v2Aruba mobility access switch useful commands v2
Aruba mobility access switch useful commands v2
 
Creating an 802 1 xv3
Creating an 802 1 xv3Creating an 802 1 xv3
Creating an 802 1 xv3
 
Rap split tunnelv2
Rap split tunnelv2Rap split tunnelv2
Rap split tunnelv2
 
Create a spectrum analysis ap group
Create a spectrum analysis ap groupCreate a spectrum analysis ap group
Create a spectrum analysis ap group
 
Aruba instant iap setup rev3
Aruba instant iap setup rev3Aruba instant iap setup rev3
Aruba instant iap setup rev3
 
Aruba wireless and clear pass 6 integration guide v1.3
Aruba wireless and clear pass 6 integration guide v1.3Aruba wireless and clear pass 6 integration guide v1.3
Aruba wireless and clear pass 6 integration guide v1.3
 
Cisco switch setup with cppm v1.2
Cisco switch setup with cppm v1.2Cisco switch setup with cppm v1.2
Cisco switch setup with cppm v1.2
 
Aruba clearpass ebook_chpt1_final
Aruba clearpass ebook_chpt1_finalAruba clearpass ebook_chpt1_final
Aruba clearpass ebook_chpt1_final
 
2012 ah vegas unified access fundamentals
2012 ah vegas   unified access fundamentals2012 ah vegas   unified access fundamentals
2012 ah vegas unified access fundamentals
 
Aruba networks webinar_wi-fi_without_interruption_sep20_2012
Aruba networks webinar_wi-fi_without_interruption_sep20_2012Aruba networks webinar_wi-fi_without_interruption_sep20_2012
Aruba networks webinar_wi-fi_without_interruption_sep20_2012
 
Spectralink airheads 2013
Spectralink airheads 2013Spectralink airheads 2013
Spectralink airheads 2013
 
8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...
 
Airheads vail 2011 pci 2.0 compliance
Airheads vail 2011   pci 2.0 complianceAirheads vail 2011   pci 2.0 compliance
Airheads vail 2011 pci 2.0 compliance
 
2012 ah vegas guest access fundamentals
2012 ah vegas   guest access fundamentals2012 ah vegas   guest access fundamentals
2012 ah vegas guest access fundamentals
 
Aruba instant the easy button for wireless gokul rajagopalan
Aruba instant the easy button for wireless gokul rajagopalanAruba instant the easy button for wireless gokul rajagopalan
Aruba instant the easy button for wireless gokul rajagopalan
 
Hello instant 0612_1a
Hello instant 0612_1aHello instant 0612_1a
Hello instant 0612_1a
 
Do d directives regarding wireless lan
Do d directives regarding wireless lanDo d directives regarding wireless lan
Do d directives regarding wireless lan
 
Gigabit wifi 802.11 ac in depth_peter thornycroft
Gigabit wifi 802.11 ac in depth_peter thornycroftGigabit wifi 802.11 ac in depth_peter thornycroft
Gigabit wifi 802.11 ac in depth_peter thornycroft
 
2012 ah emea advanced mobility design
2012 ah emea   advanced mobility design2012 ah emea   advanced mobility design
2012 ah emea advanced mobility design
 
Security intermediate practical cryptography_certs_and 802.1_x_rich langston...
Security intermediate  practical cryptography_certs_and 802.1_x_rich langston...Security intermediate  practical cryptography_certs_and 802.1_x_rich langston...
Security intermediate practical cryptography_certs_and 802.1_x_rich langston...
 

Similaire à Air group configuration howto with clearpass 6 v1.2(1)

Red_Hat_Enterprise_Linux-3-Reference_Guide-en-US.pdf
Red_Hat_Enterprise_Linux-3-Reference_Guide-en-US.pdfRed_Hat_Enterprise_Linux-3-Reference_Guide-en-US.pdf
Red_Hat_Enterprise_Linux-3-Reference_Guide-en-US.pdf
ssuser340a0c
 
Ilo scripting
Ilo scriptingIlo scripting
Ilo scripting
ahoecker
 
Informatica Command Line Statements
Informatica Command Line StatementsInformatica Command Line Statements
Informatica Command Line Statements
mnsk80
 
Sap r3 installation on windows oracle database
Sap r3 installation on windows   oracle databaseSap r3 installation on windows   oracle database
Sap r3 installation on windows oracle database
ricardopabloasensio
 

Similaire à Air group configuration howto with clearpass 6 v1.2(1) (20)

ClearPass 6.3.2 Release Notes
ClearPass 6.3.2 Release NotesClearPass 6.3.2 Release Notes
ClearPass 6.3.2 Release Notes
 
Aruba wireless and clear pass 6 integration guide v1 1.3
Aruba wireless and clear pass 6 integration guide v1 1.3Aruba wireless and clear pass 6 integration guide v1 1.3
Aruba wireless and clear pass 6 integration guide v1 1.3
 
Aruba VIA 2.0.1 User Guide Linux Edition
Aruba VIA 2.0.1 User Guide Linux EditionAruba VIA 2.0.1 User Guide Linux Edition
Aruba VIA 2.0.1 User Guide Linux Edition
 
Onboard Deployment Guide 3.9.6
Onboard Deployment Guide 3.9.6Onboard Deployment Guide 3.9.6
Onboard Deployment Guide 3.9.6
 
Red_Hat_Enterprise_Linux-3-Reference_Guide-en-US.pdf
Red_Hat_Enterprise_Linux-3-Reference_Guide-en-US.pdfRed_Hat_Enterprise_Linux-3-Reference_Guide-en-US.pdf
Red_Hat_Enterprise_Linux-3-Reference_Guide-en-US.pdf
 
ClearPass 6.4.2 Release Notes
ClearPass 6.4.2 Release NotesClearPass 6.4.2 Release Notes
ClearPass 6.4.2 Release Notes
 
ClearPass 6.4.0 Release Notes
ClearPass 6.4.0 Release NotesClearPass 6.4.0 Release Notes
ClearPass 6.4.0 Release Notes
 
Palo alto-review
Palo alto-reviewPalo alto-review
Palo alto-review
 
The Fundamentals of Internet of Everything Connectivity
The Fundamentals of Internet of Everything ConnectivityThe Fundamentals of Internet of Everything Connectivity
The Fundamentals of Internet of Everything Connectivity
 
RFP-Final3
RFP-Final3RFP-Final3
RFP-Final3
 
ClearPass 6.3.5 Release Notes
ClearPass 6.3.5 Release NotesClearPass 6.3.5 Release Notes
ClearPass 6.3.5 Release Notes
 
System z Mainframe Data with Amazon S3 and Amazon Glacier (ENT107) | AWS re:I...
System z Mainframe Data with Amazon S3 and Amazon Glacier (ENT107) | AWS re:I...System z Mainframe Data with Amazon S3 and Amazon Glacier (ENT107) | AWS re:I...
System z Mainframe Data with Amazon S3 and Amazon Glacier (ENT107) | AWS re:I...
 
Ilo scripting
Ilo scriptingIlo scripting
Ilo scripting
 
P4/FPGA, Packet Acceleration
P4/FPGA, Packet AccelerationP4/FPGA, Packet Acceleration
P4/FPGA, Packet Acceleration
 
Informatica Command Line Statements
Informatica Command Line StatementsInformatica Command Line Statements
Informatica Command Line Statements
 
Cloudera ref arch_emc_scale-out_storage
Cloudera ref arch_emc_scale-out_storageCloudera ref arch_emc_scale-out_storage
Cloudera ref arch_emc_scale-out_storage
 
Oracle database 12c advanced security guide
Oracle database 12c advanced security guideOracle database 12c advanced security guide
Oracle database 12c advanced security guide
 
Nagios Conference 2013 - Fernando Hönig - Distributed Monitoring and Cloud Sc...
Nagios Conference 2013 - Fernando Hönig - Distributed Monitoring and Cloud Sc...Nagios Conference 2013 - Fernando Hönig - Distributed Monitoring and Cloud Sc...
Nagios Conference 2013 - Fernando Hönig - Distributed Monitoring and Cloud Sc...
 
Aruba 650 Hardware and Installation Guide
Aruba 650 Hardware and Installation GuideAruba 650 Hardware and Installation Guide
Aruba 650 Hardware and Installation Guide
 
Sap r3 installation on windows oracle database
Sap r3 installation on windows   oracle databaseSap r3 installation on windows   oracle database
Sap r3 installation on windows oracle database
 

Plus de Aruba, a Hewlett Packard Enterprise company

Plus de Aruba, a Hewlett Packard Enterprise company (20)

Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard AgentsAirheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
 
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.xEMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
 
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS SwitchEMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS Switch
 
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS SwitchEMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
 
Introduction to AirWave 10
Introduction to AirWave 10Introduction to AirWave 10
Introduction to AirWave 10
 
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS SwitchEMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
 
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.xEMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
 
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads-  Getting Started with the ClearPass REST API – CPPMEMEA Airheads-  Getting Started with the ClearPass REST API – CPPM
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
 
EMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP DeploymentEMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP Deployment
 
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.xEMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
 
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)
 
Airheads Meetups: 8400 Presentation
Airheads Meetups: 8400 PresentationAirheads Meetups: 8400 Presentation
Airheads Meetups: 8400 Presentation
 
Airheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau PresentationAirheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau Presentation
 
Airheads Meetups- High density WLAN
Airheads Meetups- High density WLANAirheads Meetups- High density WLAN
Airheads Meetups- High density WLAN
 
Airheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes ArubaAirheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes Aruba
 
EMEA Airheads - Configuring different APIs in Aruba 8.x
EMEA Airheads - Configuring different APIs  in Aruba 8.x EMEA Airheads - Configuring different APIs  in Aruba 8.x
EMEA Airheads - Configuring different APIs in Aruba 8.x
 
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
EMEA Airheads - Aruba Remote Access Point (RAP) TroubleshootingEMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
 
EMEA Airheads - Multi zone ap and centralized image upgrade
EMEA Airheads - Multi zone ap and centralized image upgradeEMEA Airheads - Multi zone ap and centralized image upgrade
EMEA Airheads - Multi zone ap and centralized image upgrade
 
Bringing up Aruba Mobility Master, Managed Device & Access Point
Bringing up Aruba Mobility Master, Managed Device & Access PointBringing up Aruba Mobility Master, Managed Device & Access Point
Bringing up Aruba Mobility Master, Managed Device & Access Point
 
EMEA Airheads How licensing works in Aruba OS 8.x
EMEA Airheads  How licensing works in Aruba OS 8.xEMEA Airheads  How licensing works in Aruba OS 8.x
EMEA Airheads How licensing works in Aruba OS 8.x
 

Dernier

IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
Enterprise Knowledge
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
Earley Information Science
 

Dernier (20)

IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 

Air group configuration howto with clearpass 6 v1.2(1)

  • 1.               AirGroup  Configuration  How-­‐To  with   ClearPass  6.0.1                 TechnicalNote
  • 2. AirGroup Configuration How-To with ClearPass 6.0.1| February 2013 Copyright   ©  2012  Aruba  Networks,  Inc.  Aruba  Networks  trademarks  include   ,  Aruba  Networks®,  Aruba  Wireless   Networks®,  the  registered  Aruba  the  Mobile  Edge  Company  logo,  Aruba  Mobility  Management  System®,  Mobile  Edge   Architecture®,  People  Move.  Networks  Must  Follow®,  RFProtect®,  Green  Island®.  All  rights  reserved.  All  other   trademarks  are  the  property  of  their  respective  owners   Open  Source  Code   Certain  Aruba  products  include  Open  Source  software  code  developed  by  third  parties,  including  software  code  subject  to   the  GNU  General  Public  License  (GPL),  GNU  Lesser  General  Public  License  (LGPL),  or  other  Open  Source  Licenses.  Includes   software  from  Litech  Systems  Design.  The  IF-­‐MAP  client  library  copyright  2011  Infoblox,  Inc.  All  rights  reserved.  This   product  includes  software  developed  by  Lars  Fenneberg  et  al.  The  Open  Source  code  used  can  be  found  at  this  site::   http://www.arubanetworks.com/open_source     Legal  Notice   The  use  of  Aruba  Networks,  Inc.  switching  platforms  and  software,  by  all  individuals  or  corporations,  to  terminate  other   vendors’  VPN  client  devices  constitutes  complete  acceptance  of  liability  by  that  individual  or  corporation  for  this  action   and  indemnifies,  in  full,  Aruba  Networks,  Inc.  from  any  and  all  legal  actions  that  might  be  taken  against  it  with  respect  to   infringement  of  copyright  on  behalf  of  those  vendors.   Warranty   This  hardware  product  is  protected  by  the  standard  Aruba  warranty  of  one  year  parts/labor.  For  more  information,  refer   to  the  ARUBACARE  SERVICE  AND  SUPPORT  TERMS  AND  CONDITIONS.   Altering  this  device  (such  as  painting  it)  voids  the  warranty.             www.arubanetworks.com   1344  Crossman  Avenue   Sunnyvale,  California    94089   Phone:  408.227.4500   Fax  408.227.4550
  • 3. AirGroup Configuration How-To with ClearPass 6.0.1 | 3 Contents               Audience  ...........................................................................................................................................................................................................  7   Typographic  Conventions  .........................................................................................................................................................................  7   Contacting  Support  ......................................................................................................................................................................................  8   1.   AirGroup  Configuration  How-­‐to  with  ClearPass  6.0.1  ..............................................................................................  9   Assumptions:  ..................................................................................................................................................................................................  9   Step  1:   Controller  Configuration  ......................................................................................................................................................  9   Step  2:   ClearPass  Setup  ......................................................................................................................................................................  11   Testing  .............................................................................................................................................................................................................  17   Troubleshooting  .........................................................................................................................................................................................  18        
  • 4. 4 | AirGroup Configuration How-To with ClearPass 6.0.1    
  • 5. AirGroup Configuration How-To with ClearPass 6.0.1 | 5 Figures                   Figure  1  Configuring  a  UDP  port  for  AirGroup’s  RFC  3576  .......................................................................................................  10   Figure  3  Airgroup  AAA  profile  RFC  3576  server  ............................................................................................................................  11   Figure  4  Configure  AirGroup  Services  ................................................................................................................................................  11   Figure  5  Add  a  new  controller  for  AirGroup  Services  ..................................................................................................................  12   Figure  6  Configure  AirGroup  Services  controller  settings  .........................................................................................................  12   Figure  8  Adding  a  new  Local  User  in  CPPM  ......................................................................................................................................  13   Figure  9  Create  an  AirGroup  Administrator  .....................................................................................................................................  14   Figure  10  Create  an  AirGroup  Operator  .............................................................................................................................................  14   Figure  11  Local  Users  GUI  screen  .........................................................................................................................................................  15   Figure  12  Create  a  device  .........................................................................................................................................................................  15   Figure  13  Register  Shared  Device  .........................................................................................................................................................  16        
  • 6. 6 | AirGroup Configuration How-To with ClearPass 6.0.1    
  • 7. AirGroup Configuration How-To with ClearPass 6.0.1 | 7 Preface             Audience   This  AirGroup  Configuration  How-­‐To  with  ClearPass  6.0.1  is  intended  for  system  administrators  and  people   who  are  setting  up  AirGroup  configuration  with  ClearPass  6.0.1.   Typographic  Conventions   The  following  conventions  are  used  throughout  this  manual  to  emphasize  important  concepts.   Type Style Description Italics Used to emphasize important items and for the titles of books. Boldface Used to highlight navigation in procedures and to emphasize command names and parameter options when mentioned in text. Sample template code or HTML text Code samples are shown in a fixed-width font <angle brackets> When used in examples or command syntax, text within angle brackets represents items you should replace with information appropriate to your specific situation. For example: ping <ipaddr> In this example, you would type “ping” at the system prompt exactly as shown, followed by the IP address of the system to which ICMP echo packets are to be sent. Do not type the angle brackets.      
  • 8. 8 | AirGroup Configuration How-To with ClearPass 6.0.1 Contacting  Support   Main  Site   arubanetworks.com   Support  Site   support.arubanetworks.com   Airheads  Social  Forums  and  Knowledge   Base  and  Knowledge  Base     community.arubanetworks.com   North  American  Telephone   1-­‐800-­‐943-­‐4526  (Toll  Free)     1-­‐408-­‐754-­‐1200   International  Telephones   http://www.arubanetworks.com/support-­‐services/aruba-­‐ support-­‐program/contact-­‐support/   Software  Licensing  Site   https://licensing.arubanetworks.com/   End  of  Support  information   www.arubanetworks.com/support-­‐services/end-­‐of-­‐life-­‐ products/end-­‐of-­‐life-­‐policy/   Wireless  Security  Incident  Response   Team  (WSIRT)   http://www.arubanetworks.com/support-­‐services/security-­‐ bulletins/   Support  Email  Addresses     Americas  and  APAC   support@arubanetworks.com   EMEA   emea_support@arubanetworks.com   WSIRT  Email   Please  email  details  of  any  security   problem  found  in  an  Aruba  product.   wsirt@arubanetworks.com        
  • 9. AirGroup Configuration How-To with ClearPass 6.0.1 | 9             1. AirGroup  Configuration  How-­‐to  with  ClearPass   6.0.1   The  purpose  of  this  document  is  to  walk  through  how-­‐to  setup  AirGroup  configuration  with  ClearPass  6.0.1.   This  document  will  use  the  Integrated  Deployment  Model.   Assumptions:   1. Controller  is  running  the  latest  AirGroup  AOS  Technology  Release  (at  the  time  of  this  document  it   was  6.1.3.4-­‐Airgroup).   2. ClearPass  6.0.1  non-­‐Beta  version  is  installed.   3. IPv6  is  disabled  on  the  controller  (command:  no ipv6 enable).   4. Aruba  Wireless  and  ClearPass  6  Integration  Guide  setup  has  already  been  completed.   5. An  SSID  with  a  PSK  is  setup  for  testing.   6. An  up-­‐to-­‐date  AppleTV  is  available  for  testing.   7. An  Apple  computer  running  Mountain  Lion  (10.8.2)  or  an  iOS  device  running  iOS  6  is  available  for   testing.   Step  1: Controller  Configuration   Use  SSH  to  login  to  the  controller  and  run  the  following  command  in  configure  terminal  mode:   airgroup enable firewall cp permit proto 17 ports 21234 21234 In  the  controller  GUI,  navigate  to  Configuration-­‐>Advanced  Services-­‐>All  Profiles.  Expand  Other  Profiles.   Click  on  Airgroup  AAA  profile.  You  must  configure  a  UDP  port  for  AirGroup’s  RFC  3576.  You  cannot  use  the   default  3799.  In  the  sample  below,  UDP  port  21234  is  used.  Enter  the  port  number  in  the  ‘Configure  UDP  port   to  receive  RFC  3576  server  requests’  field  and  click  Apply.  
  • 10. 10 | AirGroup Configuration How-To with ClearPass 6.0.1 Figure  1  Configuring  a  UDP  port  for  AirGroup’s  RFC  3576     Click  on  Server  Group  under  Airgroup  AAA  profile.  Select  the  ClearPass  6  server  group  that  was  created  in   the  Aruba  Wireless  and  ClearPass  6  Integration  Guide.   Figure  2  ClearPass  6  server  group  previously  created     Click  Apply.     Click  on  RFC  3576  server  under  Airgroup  AAA  profile.  
  • 11. AirGroup Configuration How-To with ClearPass 6.0.1 | 11 Figure  3  Airgroup  AAA  profile  RFC  3576  server     Again,  use  the  RFC  3576  server  that  points  to  ClearPass  6  which  was  created  in  the  previous  setup  guide.     Click  Apply.   Step  2: ClearPass  Setup   Open  up  ClearPass  Guest  and  navigate  to  Administration-­‐>AirGroup  Services.  Click  ‘Configure  AirGroup   Services’.   Figure  4  Configure  AirGroup  Services     Click  ‘Add  a  new  controller’.    
  • 12. 12 | AirGroup Configuration How-To with ClearPass 6.0.1 Figure  5  Add  a  new  controller  for  AirGroup  Services     Enter  the  appropriate  information.     Note:  The  port  used  in  these  setup  instructions  is  21234  and  the  shared  secret  was  configured  in  the  previous   setup  guide  (where  aruba123  was  used  as  an  example).   Figure  6  Configure  AirGroup  Services  controller  settings     Click  Save  Configuration.   In  order  to  demonstrate  AirGroup,  either  an  AirGroup  Administrator  or  AirGroup  Operator  account  must  be   created.  Go  to  the  ClearPass  Policy  Manager  GUI,  and  navigate  to  Configuration-­‐>Identity-­‐>Local  Users.    
  • 13. AirGroup Configuration How-To with ClearPass 6.0.1 | 13 Figure  7  Configuration  -­‐>Identity-­‐>Local  Users  selection     Click  Add  User.     Figure  8  Adding  a  new  Local  User  in  CPPM     Create  an  AirGroup  Administrator:  
  • 14. 14 | AirGroup Configuration How-To with ClearPass 6.0.1 Figure  9  Create  an  AirGroup  Administrator     In  this  example,  as  in  past  documentation,  the  password  used  is  test123.  Click  Add.     Now  click  Add  User,  and  create  an  AirGroup  Operator:   Figure  10  Create  an  AirGroup  Operator     Click  Add  to  save  the  ‘AirGroup  Operator’  login.   The  ‘AirGroup  Administrator’  and  ‘AirGroup  Operator’  IDs  will  be  displayed  in  the  Local  Users  GUI  screen.  
  • 15. AirGroup Configuration How-To with ClearPass 6.0.1 | 15 Figure  11  Local  Users  GUI  screen     Navigate  to  the  ClearPass  Guest  GUI  and  click  the  Logout  button  so  that  you  are  presented  with  the  ClearPass   Guest  Login  page.  Enter  the  airgroup-­‐admin  login  and  password.     Click  on  Create  Device.     Figure  12  Create  a  device     The  following  page  is  displayed:  
  • 16. 16 | AirGroup Configuration How-To with ClearPass 6.0.1 Figure  13  Register  Shared  Device     For  testing  purposes,  add  your  test  AppleTV  device  name  and  MAC  address;  but  leave  the  other  fields  blank.     Click  Register  Shared  Device.    
  • 17. AirGroup Configuration How-To with ClearPass 6.0.1 | 17 Testing   Disconnect  your  AppleTV  and  OSX  Mountain  Lion/iOS  6  devices  if  they  were  previously  connected  to  the   wireless  network.  Remove  their  entries  from  the  controller’s  user  table  as  follows:   Find  the  MAC  address   “show user table” Delete  them  from  the  table   “aaa user delete mac 00:aa:22:bb:33:cc” Reconnect  both  devices.  You  should  be  able  to  connect  to  the  AppleTV  from  the  other  device.  In  order  to  limit   access  to  the  AppleTV,  open  up  the  ClearPass  Guest  GUI,  logging  in  as  the  user  that  created  the  device   (airgroup-­‐admin  or  airgroup-­‐oper  were  the  example  usernames  in  this  document)  and  navigate  to  List   Devices.  Click  on  the  test  AppleTV.  Click  Edit.  Now  add  a  username  to  the  Shared  With  field  that  is  not  the   username  being  used  to  login  with  the  OSX  Mountain  Lion/iOS  6  device.     Disconnect  and  remove  the  OSX  Mountain  Lion/iOS  6  device  from  the  controller’s  user  table.  Reconnect  the   device,  again  not  using  the  username  that  you  added  to  the  Shared  With  field.  The  AppleTV  should  not  be   available  to  this  device.   Disconnect  the  OSX  Mountain  Lion/iOS  6  device  and  delete  it  from  the  controller’s  user  table.  Reconnect   using  the  username  that  was  added  to  the  Shared  With  field.  The  OSX  Mountain  Lion/iOS  6  device  should   once  again  have  access  to  the  AppleTV.      
  • 18. 18 | AirGroup Configuration How-To with ClearPass 6.0.1 Troubleshooting   Problem:     Limiting  devices  has  no  affect.   Solution:     Make  sure  that  IPv6  is  disabled.   Problem:     OSX  Laptop  running  Mountain  Lion  can  AirPlay  to  the  AppleTV,  but  iOS  devices  cannot.   Solution:     Make  sure  that  IPv6  is  disabled.