Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

802.1x/Windows NPS/AD failed auth/redirect?

This thread has been viewed 5 times
  • 1.  802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 26, 2014 03:57 PM

    Hey All,

     

    As stated in the title I am using .1x with Windows NPS/AD to authentical users.  Has anyone figured out a way to redirect users to a Captive Portal Profile if their AD credential are no good?

     

    Thanks,

     

    Rif



  • 2.  RE: 802.1x/Windows NPS/AD failed auth/redirect?
    Best Answer

    Posted Feb 26, 2014 10:04 PM

    This is not possible.   When you enable 802.1X on a profile and the RADIUS server returns an access deny;  this will supercede any other role assignments, including the intial role and mac-auth role.      This is specific to the 802.1X on wireless; a wired 802.1X authenticated port can fail to another method or bypass.



  • 3.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 27, 2014 09:21 AM

    Thank you for the reply.  So there is nothing the controller can do with the " access deny" message from radius.  There is no way to tell the controller if you get the " access deny" message do x, y, or z?

     

    Thanks again,

     

    Rafael



  • 4.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 27, 2014 12:03 PM

    nope, deny is deny.

     

    you might look into allow and then putting in a limited role.



  • 5.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 27, 2014 12:26 PM

    Ah, ok, where would the config be for allowing the denied user into a limited role?

     

    Thanks,

     

    Rafael



  • 6.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 27, 2014 12:40 PM

    what do you use next to NPS, so your (i assume) wireless network equipment?

     

    if that is aruba you could look into setting a filter-id in NPS and use that on the controller to determine the role.



  • 7.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 27, 2014 12:47 PM

    Yea, Aruba 3400 controller.  so you are saying if a .1x user fails authentication I can have NPS send a filter-id and match that to a role assignment?

     

    Thanks,

     

    Rafael



  • 8.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 27, 2014 02:00 PM

    oh, no sorry, that wont work, you need to get the request allowed and then send a filter ID with it. deny is deny, meaning no access.

     

    dont have a NPS around current, but isnt there some final catch all statement which default to deny, cant you turn that to allow with a filter ID?



  • 9.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 27, 2014 02:53 PM

    I am not sure, gotta ask my systems guy...

     

    rafael



  • 10.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 27, 2014 03:52 PM

    Once a user fails authentication, they are not allowed access.  There is no fallback role or method allowed.  This is a limitation of the protocols and supplicants, not Aruba and not NPS.

     

    I've seen multiple use cases for this.   The idea would be to have an "allow-all-devices" method if user auth fails; then place the "allow-all-devices" into a separate role (captive portal to register for example).  It is nice in theory, but not sure if/when we'd see anything like that.



  • 11.  RE: 802.1x/Windows NPS/AD failed auth/redirect?



  • 12.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 27, 2014 04:26 PM

    Yes, but that example given is not for PEAP authentication with AD: it is using the USERS config file for management logins.   I am not sure it would work with 802.1X auths.  If you (or anyone) is aware of how this can be done, please share with the group.



  • 13.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 27, 2014 04:37 PM

    Ah yes I see that now so that case has a USER config file some how pre populated with users and their creds if a user comes on the network Aruba will check that drop down through all the users in the file until it hits that last DEFAULT Group element and return a filter-id Aruba can associate with another role.  Right, so the trick here would be to get freeradius to send something usable back to the controller when AD tell freeradius that the user's auth attempt has failed...

     

    Rafael



  • 14.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 27, 2014 09:35 PM
    I've been thinking about this... But with clearpass not NPS.

    Are you wanting to do this for all devices or just domain joined devices (ie windows laptops).



  • 15.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 28, 2014 09:31 AM

    All devices.

     

    Rafael



  • 16.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 28, 2014 12:30 PM
    Yea I know with clearpass you could do this and use a second open ssid to handle the failed authentication. And would place client in a vlan to remediate. But not sure you can with "all devices" on a dot1x. I think that is why more networks are going to certificates to authenticate.


  • 17.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 28, 2014 02:23 PM

    sdr53 how would you do this with two SSIDs? do you suggest you can forward something or such?

     

    r.ertel do you have access to your NPS? cant you create a Network Policy with pretty much no checks with just allows access? not sure if this will work, but it might.



  • 18.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Feb 28, 2014 03:34 PM
    Well it's fairly complex but based on authenticating against a database that is a log of your 802.1x network you can check to see if they authenticated and then they failed most recently. When they connect to the open ssid because they can't connect to the dot1x they get redirected to a self service password reset.

    It might be along shot for your environment. But not sure what your open ssid looks like if you even have one.


  • 19.  RE: 802.1x/Windows NPS/AD failed auth/redirect?

    Posted Mar 01, 2014 01:06 PM

    sounds interesting but feels a little dependent on how client exactly behave, does this always work for you?