Configuring HPE ANW ClearPass v25.23 (ACP2)
Welcome to this week's class
navigate to https://rubbernecks-arubanetworks.blogspot.com
Please be sure you have downloaded the learner guide and lab guide as per instructions you received from an email you would have received from HPE last week. Check your email history, spam folder etc... for keyword "OnSecure" if you cannot find the email.
- Click here for this week's lab access spreadsheet
- ask me for the link password
Tips on how to google our site for documentation
- googling for AOS-Switch-related topics
- site:hpe.com 16.10 -inurl:pdf -inurl:cx "dhcp-snooping"
- googling for AOS-CX-related topics
- site:arubanetworks.com -inurl:pdf inurl:AOS-CX inurl:10\.14 "dhcp-snooping"
- search option notes:
- site:x only searched that domain
- -inurl:x don't report links with this text in the URL
- inurl:x only report on links with text
- (ideal for finding specific version documentation)
Helpful Links
- about Aruba training and this course
- where to find more information
- vsg: Authentication Design
- aruba: Aruba Technical Product Documentation Portal
- here you find:
- Technology Briefs
- Validated Reference Designs
- Aruba Validated Designs
- Compliance Documentation related to GDPR
- airheads: community.arubanetworks.com
- abc: Airheads Broadcasting Channel
- afp: Partner Technical Webinars
- aruba: Central Demo
- where to find online documentation
- asp: Aruba Documentation Portal (all products)
- techdocs: The CLI Bank (all products)
- asp: Central Latest Online Help
- asp: Central TroubleShooting Guide (2.5.8)
- techdocs: The CLI Bank (all products)
- aps: Central OnPrem_2.5.8 User Guide
- asp: ClearPass Device Insight Online Help
- techdocs: ArubaOS_8.12_Web_Help
- aruba: EUBA Network Detection and Response (NDR) capabilities, delivered by Aruba Central
- where to find more information
- vsg: Authentication Design
- aruba: Aruba Technical Product Documentation Portal
- here you find:
- Technology Briefs
- Validated Reference Designs
- Aruba Validated Designs
- Compliance Documentation related to GDPR
- airheads: community.arubanetworks.com
- abc: Airheads Broadcasting Channel
- afp: Partner Technical Webinars
- aruba: Central Demo
- where to find online documentation
- asp: Aruba Documentation Portal (all products)
- techdocs: The CLI Bank (all products)
- asp: Central Latest Online Help
- asp: Central TroubleShooting Guide (2.5.8)
- techdocs: The CLI Bank (all products)
- aps: Central OnPrem_2.5.8 User Guide
- asp: ClearPass Device Insight Online Help
- techdocs: ArubaOS_8.12_Web_Help
- aruba: EUBA Network Detection and Response (NDR) capabilities, delivered by Aruba Central
- ClearPass Policy Manager specific links
- ClearPass Policy Manager specific links
- AOS-CX specific links
- aruba: feature-navigator.arubanetworks.com
- aruba: CX switch software feature packs
- abc: AOS-CX Software Release Technical Update
- aruba: HPE ArubaNetworking 3D Catalog
- td: AOS-S and AOS-CX Transceiver Guide Edition
- td: VSX Config Best Practices V2 (2025)
- asp: CX Documentation Portal
- asp: CX_10.13 EVPN VXLAN Guide
- asp: CX_10.13 IP Services Guide
- asp: CX_10.13 Security Guide
- asp: CX_10.13 NAE
- asp: CX_10.13 Monitoring Guide
- asp: CX_10.13 ACLs and Classifier Policies Guide - 6[34]00,81xx,8360
- asp: CX_10.13 CoPP Guide
- asp: CX_10.13 IP Routing
- asp: CX_10.13 Fundamentals Guide
- hpe: DS_4100i Series
- hpe: DS_5420 Series
- hpe: DS_6000 Series
- hpe: DS_6100 Series
- hpe: DS_6200 Series
- hpe: DS_6300 Series
- hpe: DS_6400 Series
- hpe: DS_8100 Series
- hpe: DS_8320 Series
- hpe: DS_8325 Series
- hpe: DS_8360 Series V2
- hpe: DS_8400 Series
- hpe: DS_9300 Series
- hpe: DS_10000 Series
- AOS-CX specific links
- aruba: feature-navigator.arubanetworks.com
- aruba: CX switch software feature packs
- abc: AOS-CX Software Release Technical Update
- aruba: HPE ArubaNetworking 3D Catalog
- td: AOS-S and AOS-CX Transceiver Guide Edition
- td: VSX Config Best Practices V2 (2025)
- asp: CX Documentation Portal
- asp: CX_10.13 EVPN VXLAN Guide
- asp: CX_10.13 IP Services Guide
- asp: CX_10.13 Security Guide
- asp: CX_10.13 NAE
- asp: CX_10.13 Monitoring Guide
- asp: CX_10.13 ACLs and Classifier Policies Guide - 6[34]00,81xx,8360
- asp: CX_10.13 CoPP Guide
- asp: CX_10.13 IP Routing
- asp: CX_10.13 Fundamentals Guide
- hpe: DS_4100i Series
- hpe: DS_5420 Series
- hpe: DS_6000 Series
- hpe: DS_6100 Series
- hpe: DS_6200 Series
- hpe: DS_6300 Series
- hpe: DS_6400 Series
- hpe: DS_8100 Series
- hpe: DS_8320 Series
- hpe: DS_8325 Series
- hpe: DS_8360 Series V2
- hpe: DS_8400 Series
- hpe: DS_9300 Series
- hpe: DS_10000 Series
- Manage and Monitor Hybrid IT Infrastructure
- Manage and Monitor Hybrid IT Infrastructure
- AP Datasheets
- AP Datasheets
- Remote APs
- Indoor APs
- Remote APs
- Indoor APs
- www.arubanetworks.com/assets/ds/DS_AP303Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP503Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP500Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP510Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP530Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP550Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP610Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP630Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP650Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP730Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP740Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP750Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP303Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP503Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP500Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP510Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP530Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP550Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP610Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP630Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP650Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP730Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP740Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP750Series.pdf
- Outdoor/Ruggedized APs
- www.arubanetworks.com/assets/ds/DS_AP360Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP370Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP518Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP560Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP570Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP580Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP670Series.pdf
- GW Datasheets
- Outdoor/Ruggedized APs
- www.arubanetworks.com/assets/ds/DS_AP360Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP370Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP518Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP560Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP570Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP580Series.pdf
- www.arubanetworks.com/assets/ds/DS_AP670Series.pdf
- GW Datasheets
Day 1 - Lecture Modules & Labs
M00: Introduction
M01: Introduction
Lab 1 - Testing Remote Lab Connectivity
M02: Authentication, Authorization, & Accounting
Lab 2: Configuring Authentication Sources
- 2.1: Explore CPPM Interface
- 2.2: Join CP to AD
- 2.3: Configure AD Authentication Source
- 2.4: Select Custom Attributes from AD
- 2.5: Test your AD Auth Source
- 2.1: Explore CPPM Interface
- 2.2: Join CP to AD
- 2.3: Configure AD Authentication Source
- 2.4: Select Custom Attributes from AD
- 2.5: Test your AD Auth Source
M03: External Connectivity
- youtube: ClearPass Guest with SMS
- https://regexr.com
- test the following pattern: 10\.([0-9]{1,3})\.10\.[0-9][0-9][2-4]
- youtube: ClearPass Guest with SMS
- https://regexr.com
- test the following pattern: 10\.([0-9]{1,3})\.10\.[0-9][0-9][2-4]
Lab 3: Configuring External Devices
- 3.1: Configure Network Devices
- 3.2: Configure Device Attributes and Network Device Groups
- 3.3: Configure Email Server
- 3.4: Connecting ClearPass to MDM Server
- 3.1: Configure Network Devices
- 3.2: Configure Device Attributes and Network Device Groups
- 3.3: Configure Email Server
- 3.4: Connecting ClearPass to MDM Server
M04: Endpoint Profiling
Lab 4: Endpoint Profiling
- 4.1: View Current Endpoints
- 4.2: Configure the controller for endpoint profiling
- 4.3: Configure profiling on ClearPass
- 4.4: Examine Endpoint Profile Data
- 4.1: View Current Endpoints
- 4.2: Configure the controller for endpoint profiling
- 4.3: Configure profiling on ClearPass
- 4.4: Examine Endpoint Profile Data
Day 2 - Lecture Modules & Labs
M05: Roles Enforcement Concepts
Lab 5: Roles and Enforcement
- 5.1: Plan your Enforcement
- 5.2: Create Local User Account
- 5.3: Create ClearPass Roles
- 5.4: Build Role Mapping Rules
- 5.5: Configure Enforcement Profiles
- 5.6: Configure Enforcement Policies
- 5.1: Plan your Enforcement
- 5.2: Create Local User Account
- 5.3: Create ClearPass Roles
- 5.4: Build Role Mapping Rules
- 5.5: Configure Enforcement Profiles
- 5.6: Configure Enforcement Policies
M06: Configuring Services
Lab 6: Configuring Services
- 6.1: Plan your services
- 6.2: Configure the Aruba Wireless 802.1x Service
- 6.3: Test a Failed Authentication Request
- 6.4: Testing the Aruba Wireless 802.1X Service
- 6.1: Plan your services
- 6.2: Configure the Aruba Wireless 802.1x Service
- 6.3: Test a Failed Authentication Request
- 6.4: Testing the Aruba Wireless 802.1X Service
M07: Configuring Web Services
- add the following code to your login page to utilize iframe for AUP
- <iframe src="terms.php" sandbox="allow-same-origin allow-scripts allow-popups allow-forms" frameBorder="0" style=”height:60vh;"></iframe>
- airheads: add a modal box (floating window) to CP web pages
- add the following code to your login page to utilize iframe for AUP
- <iframe src="terms.php" sandbox="allow-same-origin allow-scripts allow-popups allow-forms" frameBorder="0" style=”height:60vh;"></iframe>
- airheads: add a modal box (floating window) to CP web pages
Lab 7: Web Services
- 7.1: Upload File into Content Manager
- 7.2: Customize Built-in Skins
- 7.3: Customize Service Unavailable Page
- 7.1: Upload File into Content Manager
- 7.2: Customize Built-in Skins
- 7.3: Customize Service Unavailable Page
Day 3 - Lecture Modules & Labs
M08: Guest Access
- airheads: explaining the differences between various guest-services-templates
- airheads: MAC-Auth-vs-Allow-All-Mac-auth
- airheads: How-to-block-guest-self-registration-after-working-hours/ta-p/258349
- airheads: How to integrate IAP with CPPM to perform Captive Portal authentication
- airheads: How to change Terms of Use in Clearpass 6.x
- airheads: Web Login NAS Address configuration options in single and multi-controller deployments
- airheads: explaining the differences between various guest-services-templates
- airheads: MAC-Auth-vs-Allow-All-Mac-auth
- airheads: How-to-block-guest-self-registration-after-working-hours/ta-p/258349
- airheads: How to integrate IAP with CPPM to perform Captive Portal authentication
- airheads: How to change Terms of Use in Clearpass 6.x
- airheads: Web Login NAS Address configuration options in single and multi-controller deployments
Lab 8-A: Guest Access
- 8.1: Create Web Login Page
- 8.2: Create a Guest Account
- 8.3: Create Services for Guest in Policy Manager
- 8.4: Configure Aruba Controller for Guest
- 8.5: Test the Web Login page
- 8.1: Create Web Login Page
- 8.2: Create a Guest Account
- 8.3: Create Services for Guest in Policy Manager
- 8.4: Configure Aruba Controller for Guest
- 8.5: Test the Web Login page
Lab 8-B: Guest Authentication with MAC Caching
- 8.1: Create MAC Auth Service
- 8.2: Enable MAC Authentication on Controller
- 8.3: Testing
- 8.1: Create MAC Auth Service
- 8.2: Enable MAC Authentication on Controller
- 8.3: Testing
M09: Guest Access with Self-Registration
Lab 9: Guest Access with Self-Registration
- 9.1: Configure a Self-Registration portal
9.1.6 (page 20[34]) common student mistakebe sure to find all 3 instances ofguest_register_confirm.php
and replace with'https://{IP of your ClearPass server}/guest/guest_register_confirm.php'
the way the lab guide is written, many students only change 2 of these, but not all three
- 9.2: Configure Aruba Controller for Self-Registration
- 9.3: Testing Self-Registration
- 9.1: Configure a Self-Registration portal
9.1.6 (page 20[34]) common student mistakebe sure to find all 3 instances ofguest_register_confirm.phpand replace with'https://{IP of your ClearPass server}/guest/guest_register_confirm.php'the way the lab guide is written, many students only change 2 of these, but not all three- 9.2: Configure Aruba Controller for Self-Registration
- 9.3: Testing Self-Registration
M10: Wired Authentication
- techhub: Configuring and using dynamic (RADIUS-assigned) access control lists (nas-filter-rule)
- airheads: Bounce-port-or-disconnect-request-for-authenticatetd-user-MAC
- CX - New Features (10.08)
- automatically create vlans on switch when assigned to user by role
- port access auto-vlan
- techhub: Configuring and using dynamic (RADIUS-assigned) access control lists (nas-filter-rule)
- airheads: Bounce-port-or-disconnect-request-for-authenticatetd-user-MAC
- CX - New Features (10.08)
- automatically create vlans on switch when assigned to user by role
- port access auto-vlan
Lab 10: Wired Authentication
- 10.1: Configure the Service for Wired Authentication
- 10.2: Configure the Switch Port for 802.1X
- 10.3: Test the wired authentication port
- 10.4: Return the Configuration to Normal
- 10.1: Configure the Service for Wired Authentication
- 10.2: Configure the Switch Port for 802.1X
- 10.3: Test the wired authentication port
- 10.4: Return the Configuration to Normal
Day 4 - Lecture Modules & Labs
M11: OnGuard Configuration
Lab 11: OnGuard Configuration
- 11.1: Create a Posture Policy
- 11.2: Create Enforcement Profiles
- 11.3: Create Posture Token Based Enforcement Policy
- 11.4: Create Service to Process Health Check
- 11.5: Configure and Install OnGuard Persistent Agent
- 11.6: Testing the OnGuard Persistent Agent
- 11.1: Create a Posture Policy
- 11.2: Create Enforcement Profiles
- 11.3: Create Posture Token Based Enforcement Policy
- 11.4: Create Service to Process Health Check
- 11.5: Configure and Install OnGuard Persistent Agent
- 11.6: Testing the OnGuard Persistent Agent
M12: OnGuard in Enforcement
Lab 12: OnGuard Enforcement
- 12.1: Modify the Enforcement Policy
- 12.2: Modify the Wireless Service
- 12.3: Modify the Health Check Service
- 12.4: Testing
- 12.1: Modify the Enforcement Policy
- 12.2: Modify the Wireless Service
- 12.3: Modify the Health Check Service
- 12.4: Testing
M13: Onboard Provisioning
Lab 13: Onboard Configuration
- 13.1: Configure Onboard as Root CA
- 13.2: Configure Onboard Network Settings
- 13.3: Configure Onboard Configuration Profile & Provisioning Settings
- 15.4: Create Onboard Services
- 15.5: Configure BYOD-Provision role on Controller
- 15.6: Testing Onboard
- 13.1: Configure Onboard as Root CA
- 13.2: Configure Onboard Network Settings
- 13.3: Configure Onboard Configuration Profile & Provisioning Settings
- 15.4: Create Onboard Services
- 15.5: Configure BYOD-Provision role on Controller
- 15.6: Testing Onboard
M14: Onboard Administration
Lab 14: Onboard Administration
- 14.1: Deny Access to Deleted User
- 14.2: Test OCSP
- 14.3: Deny Access to the Device
- 14.1: Deny Access to Deleted User
- 14.2: Test OCSP
- 14.3: Deny Access to the Device
Day 5 - Lecture Modules & Labs
M15: Administrative Operations
Lab 15: Administrative Operations
- 15.1: Certificate Stores
- 15.2: Licenses
- 15.3: Backups and Logs
M16: Administrative Access
Lab 16: Administrative Operations
- 16.1: Guest Operator Login
- 16.2: Create new Guest Admin Account
- 16.3: Test Guest Operator Account
- 16.4: Policy Manager Admin Access for AD users
- 16.5: Policy Manager Admin privileges
- 16.6: TACACS+ Admin Access to Aruba Devices
M17: Insight Reports
Lab 17: Insight Reports
- 17.1: Configuring Insight
- 17.2: Explore the Insight Dashboard
- 17.3: Creating Reports in Insight
- 17.4: Alerts and Watchlist
M18: Cluster (part of expert course)
- cluster certificates FIELD ADVISORY CLUSTERING IN 6.8
- The process of clustering CPPM requires 2 certificate validations
- HTTPS certificate validation
- 6.8 mandates the validation of HTTPS certificate between cluster nodes
- self signed certs will cause subscribers to fail with
- make subscriber failed, “GET failed, Will retry”
- solution 1: recommended
- CPPM nodes are signed by a Public CA.
- A wildcard or a cert containing the FQDN for all the nodes in the cluster within the SAN signed by a known Public CA can be used
- Ensure the entire chain including the Root and Intermediates of the Signing Certificate Authority (CA) are enabled in the Trust list of the Publisher.
- To enable a trusted CA, navigate to Administration > Certificates > Trust List.
- Enable the CA to be trusted for “Usage = Others”.
- solution 2: not recommended (it ignores trust validation for the nodes joining the cluster)
- Login to the CLI of the CPPM node to be added as a subscriber using the appadmin credentials.
- Once logged in, issue the command as shown below:
- [appadmin@CPPM2]# cluster make-subscriber -i <Publisher IP> -V
- Expiration of HTTPS certificate does not affect the existing cluster.
- This works on relaxing HTTPS certificate requirements, but not Database certificate requirements
- Database certificate validation
- you can use self-signed DB cert on your publisher, it's SAN field will be DNS:x.x.x.x (ip address of self)
- however, you must export that cert, then import that cert into the new cluster nodes trust list before it can join your publisher as a subscriber
- see the end of lab 18 for instructions on how to:
- export the cert in p12 format
- use openssl.exe to convert the p12 to PEM format which can be imported into the new cluster nodes trust list
- but, best practice is to use a public CA to create certs for each cluster node, be sure the SAN for each is set to DNS:x.x.x.x (ip address of node it is installed on)
- it cannot use the SAN IP:x.x.x.x format
- be sure to install your CA's public cert the cluster's root chain of trust
- this means you no longer need to install your trust anchors public certs in your nodes before you have them join your cluster
- Lab 18: Cluster
- 18.1: Enabling Clustering
- 18.1.20: (on page 490)
- after completing step 18.1.20 you MUST go to page 513 and complete all steps from the paragraph titled "Certificate conversion process from .p12 to .pem", then return to page 490 and continue from step 21
- 18.2: Monitoring Clustering
- 18.3: Configuring High Availability
- 18.4: Testing High Availability
Appendix
- Acronyms or Key terms
- 2.5.29.19 - Basic Constraints: (X.509 Certificate Extension)
- This extension indicates if the subject may act as a CA, with the certified public key being used to verify certificate signatures
- This is required for Cluster DB Certificates as of CPPM >= 6.8
- Icon Key
- icon key slide from pptx
- download if you want to copy the images
- Lab Access Errata
- if experiencing any problems with remote lab access (WebGate):
- be sure your browser is in private (incognito) mode
- restart your browser and clear your cache and cookies
- do not try to login unless you are 100 percent sure the login page is fully loaded
- during login to Central, did you select the SSO option?
- if you need to restart your windows host
- in cmd.com type "shutdown /r /t 0"
Comments
Post a Comment