The Web Page Templates

ClearPass Guest provides the following templates for simple Web pages. You can use these templates as they are, or edit any of their properties to suit your needs, or copy them to use as a basis for new Web pages. These templates are available at Configuration > Pages > Web Pages.

Browser Unsupported Page Template

The Browser Unsupported template can be used to show a message advising the guest that their browser is not supported.

Figure 1  The Page Displayed by the Default Browser Unsupported Template

Jailbroken Device Page Template

The Jailbroken Device template can be used to show a message advising the guest that the iOS or iPadOS device has been modified, or jailbroken.

Figure 2  The Page Displayed by the Default Jailbroken Device Template

Posture Check Page Template

The Posture Check template can be used to show a message advising the guest that the device does not meet the organization’s minimum security requirements (detected by OnGuard).

Figure 3  The Page Displayed by the Default Posture Check Template

Posture Results Page Template

The Posture Results template can be used to notify end users of posture results for unhealthy clients after OnGuard’s health checks. When this feature is enabled, the OnGuard Agent will display a new Posture Results web page to users in their default browser if a client is unhealthy. The Posture Results page lists each failed scan and its results.

To enable this page:

1. Go to Policy Manager > Configuration > Enforcement > Profiles > Add.

2. In the Template field, select Agent Enforcement.

3. On the Attributes tab, add the Show Posture Results in Guest Page attribute. Set the value for the attribute to true, and complete the rest of the fields as needed.

4. To make any changes to the default configuration of this page, go to Guest > Configuration > Pages > Web Pages, click the Posture Results row, and then click Edit.

Figure 4  The Page Displayed by the Default Posture Results Template

Quarantined Blocked Page Template

The Quarantined Blocked template can be used to show a message advising the guest that their device has been quarantined.

Figure 5  The Page Displayed by the Default Quarantined Blocked Template

Service Unavailable Page Template

The Service Unavailable template can be used to show a message advising the guest that service is temporarily unavailable.

Figure 6  The Page Displayed by the Default Service Unavailable Template

Terms and Conditions Page Template

The Terms and Conditions template can be used to provide information to the user about the terms and conditions of use.

Figure 7  The Page Displayed by the Default Terms and Conditions Template

WebCC Blocked Page Template

The WebCC Blocked template can be used to show a message advising the guest that a web page they are trying to access has been blocked.

Figure 8  The Page Displayed by the Default WebCC Blocked Template

OnGuard Remediation Wizard Custom Interface Page Templates

You can configure ClearPass OnGuard to show end users a custom interface, or wizard, that guides them through the remediation process if their device is quarantined. When this feature is enabled and OnGuard needs to run a custom remediation script, the wizard tells the user why the device was denied network access and describes the tasks that are required to fix the problem. While the script is being executed and new health checks are run, pages showing status and progress messages are displayed. The user can close the wizard at any time and the remediation script will continue to execute in the background. This feature is only available for the Windows operating system.

Configuration of the remediation wizard is done partly in Policy Manager and partly in Guest:

The custom user interface must first be enabled at Policy Manager > Administration > Agents and Software Updates > OnGuard Settings.

Links are then provided there to the Guest > Configuration > Pages > Web Page Settings form described in this section, where you can configure the pages and customize the text, logo, and images.

In Policy Manager, configure the Agent Enforcement profile and configure the Show Custom UI for Custom Scripts attribute for it.

In Policy Manager, configure the Agent Script Enforcement profile and configure the Success Message, Failure Message, Progress Message, and Description attributes for it.

Complete instructions for the configuration process are provided in the ”About the OnGuard Custom Interface and the Remediation Process” section of the ClearPass Policy Manager User Guide.

The OnGuard remediation wizard includes five Web page templates, each of which can be customized with logo, text, and images. When you configure the custom user interface in Policy Manager’s OnGuard Settings, the links provided to ClearPass Guest’s Web Page Settings form let you configure and customize the following pages of the wizard. These pages are not displayed in the Web Pages list of templates unless you have configured them:

Start page — The start page of the custom interface lets the user know that their device did not meet health requirements and that automatic remediation actions will be performed, after which it will be connected to the network.

Progress page — While the remediation actions are being executed, the progress page of the custom interface displays an indicator and requests that the user not disconnect their device.

Finish page, success — When the remediation is successfully completed, the success page lets the user know it was successful, and that after OnGuard scans and verifies their system it will connect them to the network.

Finish page, reboot — If the remediation is successfully completed but any of the remediation actions require a system reboot, the reboot page lets the user know it was successful, and that after OnGuard scans, verifies, and reboots their system it will connect them to the network.

Finish page, error — If remediation of the device could not be completed, the error page lets the user know it was unsuccessful, lists the issues that could not be resolved, provides a link to Support, and informs the user that the device is not connected to the network.