Endpoint Profiling with Aruba Clearpass

Cole
Getting noticed

Endpoint Profiling with Aruba Clearpass

Hello, 

 

I am trying to enable endpoint profiling from a subnet using DHCP options sent to clearpass. DHCP is currently handled by the dashboard so I am not sure if I need to use DHCP relay or there are options that need t be configured. I have serached online and cannot find anything addressing my issue. 

 

Has anyone had experience with this that may be able to give some insight?

 

Thanks in advance!

5 Replies 5
alemabrahao
Kind of a big deal
Kind of a big deal

From the dashboard in what sense? You say the DHCP configuration is on the dashboard, but is your switch acting as the DHCP server?

 

 

If your Meraki switch is currently acting as the DHCP server, you cannot forward DHCP packets to ClearPass for profiling. You’ll need to switch to DHCP relay mode.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Cole
Getting noticed

Yes, the switch is currently acting as the DHCP server:

Cole_0-1761658547631.png

If I switch to relay mode, can I still use the core switch as the DHCP server?

Mloraditch
Kind of a big deal
Kind of a big deal

You cannot. However if you have another switch capable of relaying, you could create interfaces there using another IP on the same VLAN and then relay to clearpass.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Cole
Getting noticed

Is there nothing that can be done with the DHCP options that may send the information needed? 

Mloraditch
Kind of a big deal
Kind of a big deal

No, Meraki doesn't support both relaying and running DHCP on the same device. You  must separate those functions if both are needed.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Get notified when there are additional replies to this discussion.