ClearPass

The BYOD ClearPass Screen displays all configured ClearPass Policy Manager (CPPM) Servers and is used to configure the connection to the CPPM Server, configure the CPPM server as a RADIUS Server, and assign the CPPM server to switches on the network. The screen is also used to edit and delete servers. Once the CPPM Server is configured, you can also launch the ClearPass Policy Manager Web interface by selecting a server and clicking on the Launch button.

ClearPass provides Bring Your Own Device (BYOD) access to the network. The Alcatel-Lucent Enterprise BYOD solution integrates with ClearPass Policy Manager (CPPM), using the RADIUS (RFC 3576) Change of Authorization (CoA) to achieve this functionality. OmniVista supports some portions of the configuration to facilitate the solution, including:

Configuring a ClearPass Server

Click on the Create icon. Complete the fields as described below, then click on the Create button. When you are finished, select the checkbox next to the server and click on the Apply to Devices button to assign the server to switches on the network. Note that certain key fields are pre-filled with default values. It is recommended that you use the default values for these fields.

Management

Database

RADIUS Server

Redirect Options

The redirect option is only supported on OS6860 Switches (AOS 8.1.1.R01 and later).

Note: The Insight Database must be enabled on the ClearPass Server for OmniVista to gather Locator information. In the CPPM application, go to: Administration - Server Configuration, then click on the Server in the table to bring up the following screen. Make sure the Enable Profile and Enable Insight checkboxes are checked.

 

Assigning a ClearPass Server

OmniVista will configure CPPM as a RADIUS Server on the selected switches. It also sets 802.1x authentication, MAC authentication, and accounting to point to the CPPM RADIUS Server entry. It also sets Redirect Server to be the CPPM Server, allowing the switch to accept redirect messages from the RADIUS Server for Captive portal (Web) authentication with CCPM. On CPPM, the selected switches will be added to the list of Network Access Devices (NAD) with the CoA flag and CoA port. The result is the successful pairing of the CPPM Server and the switches. If specified, Allowed Servers are also configured on AOS 8.1.1 switches.

When you click the Apply to Devices button, the Assignment Screen appears. Configure any options, as described below, then use the "Assign Switch" Add/Remove buttons to select the switch(es) and click Apply or Override. ("Override" will override any previous configurations.)

Editing a ClearPass Server

Select the ClearPass Server you want to edit and click on the Edit icon to bring up the "Edit ClearPass Server" Screen. Edit the fields as described above then click on the Save button to save the changes to the server.

Deleting a ClearPass Server

To delete a ClearPass Server(s), select the server(s) in the table and click on the Delete icon, then click OK at the confirmation prompt.

Launching the ClearPass Web Interface

Once the connection to the CPPM Server has been configured, click on the Launch button to launch the ClearPass Policy Manager web interface. This is where you will configure ClearPass authentication and network access policies. See the ClearPass Policy Manager On-Line Help for ClearPass configuration information.