Security

last person joined: 17 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Authentication with Windows Server 2008 (AD) as LDAP.

This thread has been viewed 3 times
  • 1.  Authentication with Windows Server 2008 (AD) as LDAP.

    Posted Nov 27, 2012 02:25 AM

    Hi all.

     

    I want to set up ARUBA-Controller, and to use Active-Directry as LDAP Server.
    Controller logged "To support this configuration dot1x profile 'ldap' should have termination enabled and eaptype set to eap-tls or eap-peap with gtc as the only innereaptype".
    So, termination is enabled on controller and set eap-type EAP-PEAP and EAP-GTC.

    After configured it, I tried "aaa test-server pap [ldap] [user] [pass]" and terminal was shown "Authentication successful".
    However, I actually tried to connect WLAN of LDAP-authentication, authentication was failed....
    I typed command "show auth-tracebuf", shown this...

     

    Nov 27 21:13:56 station-up * 70:1a:04:8f:XX:XX 00:24:6c:d6:XX:XX - - wpa2 aes
    Nov 27 21:13:56 station-term-start * 70:1a:04:8f:XX:XX 00:24:6c:d6:XX:XX 1 -
    Nov 27 21:13:56 eap-term-start -> 70:1a:04:8f:XX:XX 00:24:6c:d6:XX:XX/ldap - -
    Nov 27 21:13:56 station-term-start * 70:1a:04:8f:XX:XX 00:24:6c:d6:XX:XX 1 -
    Nov 27 21:13:56 station-term-end * 70:1a:04:8f:XX:XX 00:24:6c:d6:XX:XX/ldap 11405 - failure
    Nov 27 21:13:56 station-down * 70:1a:04:8f:XX:XX 00:24:6c:d6:XX:XX - -

     

    "eap-term-start" is failure, and I seem that is cause authentication-failure.
    Wireless Client used MS-CHAPv2, because can't use EAP-GTC.
    If I want to use LDAP server, MUST WirelessClient use EAP-GTC for auth-method?
    We use Windows7 and XP for Wireless Client.

    Should I get EAP-GTC Plug-in?

     

    so what may be the solution for this other than using radius server.



  • 2.  RE: Authentication with Windows Server 2008 (AD) as LDAP.

    EMPLOYEE
    Posted Nov 27, 2012 05:52 AM

    You must use EAP-GTC with LDAP if you want to use Encryption.

     

    If you don't want to install the EAP-GTC plugin on all your clients, you can use Captive Portal authentication or use WPA2-Preshared key authentication.

     



  • 3.  RE: Authentication with Windows Server 2008 (AD) as LDAP.

    Posted Nov 27, 2012 11:35 PM

    Thank you for your reply.

     

    muh.... If we use Windows Server as Auth-server, we should adopt NPS as RADIUS server, doesn't it?

     



  • 4.  RE: Authentication with Windows Server 2008 (AD) as LDAP.



  • 5.  RE: Authentication with Windows Server 2008 (AD) as LDAP.

    Posted Dec 02, 2012 09:18 PM

    Thank you cjoseph!!

    I understood well about LDAP-solutinon.