Hello Herman, great video again, thank you very much!!! One question: is it possible to use a wildcard certificate in the instant ap for captive portal or do we need a certificate with a special CN pointing to the instant ap?
Captive portal requires a public trusted certiifcate on the ClearPass, and one on the APs/controller, regardless if the APs are deployed on campus or as RAP. For Enterprise logon as in WPA2/3-Enterprise, that requires a trusted certificate as well, but that cert is preferred a private issued certificate. Check the video on EAP-TLS in this series for more info on that.
@@hermanrobers thank you very much. can you possibly link the video to that EAP-TLS thing because i couldn't find it without digging through years of Aruba videos.
Are you using ClearPass Guest? Do you refer to MAC Caching? If there is MAC Caching, and you return in ClearPass the username of the guest that initially authenticated in the IETF:Username attribute, that value will be shown in the AP or controller. The default wizards for Guest with MAC Caching will set that up. Is that an answer to your question?
Got it but don't know where it need to configure.. my solution is IT admin based solution is their any chances to get user name once mac caching is done .
Very helpful - good troubleshooting information.Thanks.
excellent as always, thanks
Hello Herman, great video again, thank you very much!!! One question: is it possible to use a wildcard certificate in the instant ap for captive portal or do we need a certificate with a special CN pointing to the instant ap?
Does an implementation of local and remote Campus AP's require certificates to allow guest logon and enterprise logon?
Captive portal requires a public trusted certiifcate on the ClearPass, and one on the APs/controller, regardless if the APs are deployed on campus or as RAP. For Enterprise logon as in WPA2/3-Enterprise, that requires a trusted certificate as well, but that cert is preferred a private issued certificate. Check the video on EAP-TLS in this series for more info on that.
@@hermanrobers thank you very much. can you possibly link the video to that EAP-TLS thing because i couldn't find it without digging through years of Aruba videos.
Hi Herman, in my guest solution I'm getting the Mac address in mac auth service.. could you pls help me to get user name in place of it..
Are you using ClearPass Guest? Do you refer to MAC Caching? If there is MAC Caching, and you return in ClearPass the username of the guest that initially authenticated in the IETF:Username attribute, that value will be shown in the AP or controller. The default wizards for Guest with MAC Caching will set that up. Is that an answer to your question?
Got it but don't know where it need to configure.. my solution is IT admin based solution is their any chances to get user name once mac caching is done .