Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Can ClearPass base enforcement off of Google Apps OU?

This thread has been viewed 4 times
  • 1.  Can ClearPass base enforcement off of Google Apps OU?

    Posted Jun 03, 2016 10:47 AM

    Is there support for ClearPass to integrate with Google Apps? I have a K-12 customer who is hoping to authenticate faculty, staff and students against their Google Apps setup and distinguish their role by their OU within Google. Faculty and staff have AD accounts, but students do not so AD is not going to be an option. 



  • 2.  RE: Can ClearPass base enforcement off of Google Apps OU?

    EMPLOYEE
    Posted Jun 03, 2016 10:49 AM
    Web authentication I assume? 

    The orgUnitPath will come through in the social_vip attribute for the endpoint.


  • 3.  RE: Can ClearPass base enforcement off of Google Apps OU?

    Posted Jun 06, 2016 09:09 AM

    We would like to do RADIUS with Google Apps as the authentication source. 



  • 4.  RE: Can ClearPass base enforcement off of Google Apps OU?

    EMPLOYEE
    Posted Jun 06, 2016 09:12 AM
    What authentication method are you looking to use? 802.1X? Web authentication? 


  • 5.  RE: Can ClearPass base enforcement off of Google Apps OU?

    Posted Jun 06, 2016 09:15 AM

    @cappalli wrote:
    What authentication method are you looking to use? 802.1X? Web authentication? 

    802.1X would be the preferred method.



  • 6.  RE: Can ClearPass base enforcement off of Google Apps OU?
    Best Answer

    EMPLOYEE
    Posted Jun 06, 2016 09:21 AM
    The only supported 802.1X method directly off of Google Apps would be EAP-TTLS and would require a proxy to a Free RADIUS server running an Oauth2 authenticator. EAP-TTLS also requires significant client configuration cross platforms. 

    The recommendation would be EAP-TLS using Onboard. The users would authenticate with their Google Apps credentials on the web portal during Onboarding. 

    If you don't want to use Onboard, your only option for direct Google Apps authentication would be web authentication with MAC-caching. 

    If you have the user accounts synced to a local directory server (AD/LDAP), you can leverage EAP-PEAP or EAP-TTLS. Both of which would be considered fairly insecure in an unmanaged environment. 


  • 7.  RE: Can ClearPass base enforcement off of Google Apps OU?

    Posted Jun 06, 2016 09:27 AM

    Thanks, Tim. That's exactly the info I needed.

     

    Does this support Google Apps for Education or only Google Apps for Business? Thanks.


    @cappalli wrote:
    The only supported 802.1X method directly off of Google Apps would be EAP-TTLS and would require a proxy to a Free RADIUS server running an Oauth2 authenticator. EAP-TTLS also requires significant client configuration cross platforms. 

    The recommendation would be EAP-TLS using Onboard. The users would authenticate with their Google Apps credentials on the web portal during Onboarding. 

    If you don't want to use Onboard, your only option for direct Google Apps authentication would be web authentication with MAC-caching. 

    If you have the user accounts synced to a local directory server (AD/LDAP), you can leverage EAP-PEAP or EAP-TTLS. Both of which would be considered fairly insecure in an unmanaged environment. 

     



  • 8.  RE: Can ClearPass base enforcement off of Google Apps OU?

    EMPLOYEE
    Posted Jun 06, 2016 09:31 AM
    They both can use Oauth2 and SAML so both should work. 


  • 9.  RE: Can ClearPass base enforcement off of Google Apps OU?

    Posted Oct 24, 2016 03:58 PM

    Hi Tim,

     

    Would you mind sharing where I might find some more detail on EAP-TLS / OnBoard / Google Apps Web Portal? I have access to Arubapedia and ASE but dotn see much for reference. 

     

    I am not sure I understand how I would present a Google Education login during the OnBoarding process. 

     

    This would be very beneficial to a few of our customers!

     

    Thanks



  • 10.  RE: Can ClearPass base enforcement off of Google Apps OU?

    EMPLOYEE
    Posted Oct 24, 2016 04:36 PM

    In your provisioning profile Web Login configuration, enable social providers and then select Google Apps from the dropdown and follow the instructions to get eveyrthign configured.



  • 11.  RE: Can ClearPass base enforcement off of Google Apps OU?

    Posted Oct 24, 2016 04:49 PM

    Thanks Tim. It looks like it uses SAML iDP. I will start researching. 



  • 12.  RE: Can ClearPass base enforcement off of Google Apps OU?

    EMPLOYEE
    Posted Oct 24, 2016 04:54 PM
    The social login method should be using OAuth2.


  • 13.  RE: Can ClearPass base enforcement off of Google Apps OU?

    EMPLOYEE
    Posted Jun 03, 2016 10:58 AM

    @trandall wrote:

    Is there support for ClearPass to integrate with Google Apps? I have a K-12 customer who is hoping to authenticate faculty, staff and students against their Google Apps setupGoo and distinguish their role by their OU within Google. Faculty and staff have AD accounts, but students do not so AD is not going to be an option. 


    Is this Google Apps for Business or Google Apps for Education (you said K-12, but I want to make sure)..



  • 14.  RE: Can ClearPass base enforcement off of Google Apps OU?

    Posted Jun 06, 2016 09:08 AM

    It is Google Apps for Education.