Fortinet black logo

New Features

Support multiple fabric connectors to Aruba ClearPass in the same ADOM

Copy Link
Copy Doc ID b5bbfe47-438c-11ea-9384-00505692583a:669688
Download PDF

Support multiple fabric connectors to Aruba ClearPass in the same ADOM

You can create multiple Aruba ClearPass connectors in each FortiManager ADOM, and then add them to a user group object, which you can install to FortiGates via a policy package. After the policy package is installed, FortiGate can use the multiple ClearPass connectors in the ADOM to connect to multiple CCPM (Configure ClearPass Policy Manager) servers.

Following is an overview of how to use multiple ClearPass connectors:

  1. Create multiple ClearPass connectors in an ADOM. See Creating multiple ClearPass connectors in an ADOM.
  2. Get roles and users from ClearPass. See Getting roles and users from ClearPass.
  3. Create a user group object that references multiple ClearPass connectors. See Creating user groups .
  4. Add the user group to a policy package, and install the policy package to FortiGate. See Installing policy packages to FortiGate.

    FortiGate uses the ClearPass connectors to connect to multiple CCPM servers.

This example assumes that Aruba ClearPass is already set up.

Creating multiple ClearPass connectors in an ADOM

To create multiple Aruba ClearPass connectors:
  1. Ensure you are in the correct ADOM.

    This example uses the root ADOM.

  2. Create a Clear Pass connector.
    1. Go to Fabric View > Fabric Connectors.
    2. Click Create New > ClearPass, and click Next.

    3. Complete the options, and click OK.

    The ClearPass connector is created.

  3. Create another ClearPass connector.

    The multiple fabric connectors for Aruba ClearPass are displayed in the root ADOM.

Getting roles and users from ClearPass

To get roles and users from ClearPass:
  1. Go to Policy & Objects > Object Configurations > Fabric Connectors >SSO/Identity.
  2. Double-click a ClearPass connector to open it for editing, and click Apply & Refresh.

    FortiManager retrieves the roles and users from ClearPass.

  3. Repeat this procedure for all ClearPass connectors in the ADOM.

Creating user groups

To create user groups:
  1. Go to Policy & Objects > Object Configurations > User & Device > User Groups.
  2. Click Create New.
  3. In the Group Name box, type a name for the group.
  4. Beside Type, select FSSO/SSO Connectors, and select the Aruba ClearPass connectors.
  5. Set the remaining options, and click OK.

Installing policy packages to FortiGate

To install policy packages to FortiGate:
  1. Go to Policy & Objects > Policy Packages.
  2. Use the new user group in a policy package, and install the policy package to FortiGate.

    After the policy package is installed to FortiGate, FortiGate can use multiple CCPM servers. FortiGate distinguishes between multiple connectors by the user names contained in each ClearPass connector.

Support multiple fabric connectors to Aruba ClearPass in the same ADOM

You can create multiple Aruba ClearPass connectors in each FortiManager ADOM, and then add them to a user group object, which you can install to FortiGates via a policy package. After the policy package is installed, FortiGate can use the multiple ClearPass connectors in the ADOM to connect to multiple CCPM (Configure ClearPass Policy Manager) servers.

Following is an overview of how to use multiple ClearPass connectors:

  1. Create multiple ClearPass connectors in an ADOM. See Creating multiple ClearPass connectors in an ADOM.
  2. Get roles and users from ClearPass. See Getting roles and users from ClearPass.
  3. Create a user group object that references multiple ClearPass connectors. See Creating user groups .
  4. Add the user group to a policy package, and install the policy package to FortiGate. See Installing policy packages to FortiGate.

    FortiGate uses the ClearPass connectors to connect to multiple CCPM servers.

This example assumes that Aruba ClearPass is already set up.

Creating multiple ClearPass connectors in an ADOM

To create multiple Aruba ClearPass connectors:
  1. Ensure you are in the correct ADOM.

    This example uses the root ADOM.

  2. Create a Clear Pass connector.
    1. Go to Fabric View > Fabric Connectors.
    2. Click Create New > ClearPass, and click Next.

    3. Complete the options, and click OK.

    The ClearPass connector is created.

  3. Create another ClearPass connector.

    The multiple fabric connectors for Aruba ClearPass are displayed in the root ADOM.

Getting roles and users from ClearPass

To get roles and users from ClearPass:
  1. Go to Policy & Objects > Object Configurations > Fabric Connectors >SSO/Identity.
  2. Double-click a ClearPass connector to open it for editing, and click Apply & Refresh.

    FortiManager retrieves the roles and users from ClearPass.

  3. Repeat this procedure for all ClearPass connectors in the ADOM.

Creating user groups

To create user groups:
  1. Go to Policy & Objects > Object Configurations > User & Device > User Groups.
  2. Click Create New.
  3. In the Group Name box, type a name for the group.
  4. Beside Type, select FSSO/SSO Connectors, and select the Aruba ClearPass connectors.
  5. Set the remaining options, and click OK.

Installing policy packages to FortiGate

To install policy packages to FortiGate:
  1. Go to Policy & Objects > Policy Packages.
  2. Use the new user group in a policy package, and install the policy package to FortiGate.

    After the policy package is installed to FortiGate, FortiGate can use multiple CCPM servers. FortiGate distinguishes between multiple connectors by the user names contained in each ClearPass connector.