Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Can ClearPass use 2 active directory for 8021.x authentication?

This thread has been viewed 20 times
  • 1.  Can ClearPass use 2 active directory for 8021.x authentication?

    Posted Aug 15, 2018 01:26 PM

    Hi, Can ClearPass use more than 1 active directory (different domain) for different user group 8021.x authentication?  If yes, it is possible for this different  domain users to connect to same SSID? Please advise, thanks in advance.



  • 2.  RE: Can ClearPass use 2 active directory for 8021.x authentication?

    EMPLOYEE
    Posted Aug 15, 2018 01:30 PM
    Yes


  • 3.  RE: Can ClearPass use 2 active directory for 8021.x authentication?

    Posted Aug 15, 2018 01:43 PM

    Thanks for your reply. Can you advise how to create service on clearpass if this 2 domain users connect to same SSID? create one service with 2 authentication sources?  In such case, Clearpass still need to integrat with 1 AD domain, right? 



  • 4.  RE: Can ClearPass use 2 active directory for 8021.x authentication?

    EMPLOYEE
    Posted Aug 15, 2018 01:45 PM
    Yes, add a second auth source. If you’re using legacy EAP methods like PEAP, you’ll need to join ClearPass to both domains.


  • 5.  RE: Can ClearPass use 2 active directory for 8021.x authentication?

    Posted Aug 15, 2018 01:47 PM

    If join both domains, then also need to install 2 radius server certificates on clearpass, right? 



  • 6.  RE: Can ClearPass use 2 active directory for 8021.x authentication?

    EMPLOYEE
    Posted Aug 15, 2018 02:00 PM
    No. The authentication source has nothing to do with the EAP server certificate.


  • 7.  RE: Can ClearPass use 2 active directory for 8021.x authentication?

    Posted Aug 15, 2018 02:05 PM

    But if don't install private radius certificates which generated on both AD, then Clearpass cannot trust the AD source and will give error. I tried one AD integration with Clearpass before, have to installed the certificate. Please advise whether I am right. Thanks.



  • 8.  RE: Can ClearPass use 2 active directory for 8021.x authentication?

    EMPLOYEE
    Posted Aug 15, 2018 02:14 PM
    If you want to use multiple EAP server certificates, users need to authenticate with their fully qualified username and you would use two different services.

    If not, you’ll have to choose one of the certs and configure the other clients to trust it.


  • 9.  RE: Can ClearPass use 2 active directory for 8021.x authentication?

    Posted Aug 15, 2018 02:23 PM

    If this 2 domain users connect to same SSID, how to use 2 services to filter the users? 

     

    If not use EAP certificate, you mean just install first AD radius certificate on Clearpss, and configure Clearpass to trust second AD? how to configure Clearpass to trust AD without installing radius certificate? 

     

     



  • 10.  RE: Can ClearPass use 2 active directory for 8021.x authentication?

    EMPLOYEE
    Posted Aug 15, 2018 02:27 PM
    You should work with your ClearPass partner.


  • 11.  RE: Can ClearPass use 2 active directory for 8021.x authentication?

    Posted Aug 15, 2018 02:32 PM

    Sorry, currently no clearpass partner, can you help answer how to filter different domain users if they connecting to same SSID? Urgent! thanks a lot. 



  • 12.  RE: Can ClearPass use 2 active directory for 8021.x authentication?

    EMPLOYEE
    Posted Aug 15, 2018 02:35 PM
    Authentication:Full-Username ENDS_WITH @domain.xyz


  • 13.  RE: Can ClearPass use 2 active directory for 8021.x authentication?

    Posted Aug 15, 2018 02:38 PM

    thanks a lot for your kind reply. Have a good day!