Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass 802.1x authentication

This thread has been viewed 4 times
  • 1.  ClearPass 802.1x authentication

    Posted Nov 09, 2017 12:28 PM

    Super frustrated rihgt now trying to get our IP phones to work on a wired port that is doing 802.1x auth.  Isnt there a way to setup in the service that if Clearpass determines a device to be a printer or a ip phone that it allows access?  That is basically what we want. We do not want to have to MAC auth as that is so messy with keeping the database up to date. 



  • 2.  RE: ClearPass 802.1x authentication

    EMPLOYEE
    Posted Nov 09, 2017 12:31 PM
    That would be part of a MAC auth configuration. There is nothing to maintain. Did you look at the Solutions Guide for Wired Policy Enforcement? It shows examples of that.


  • 3.  RE: ClearPass 802.1x authentication

    Posted Nov 09, 2017 12:33 PM

    I've tried digging through it but I must be missing it. 



  • 4.  RE: ClearPass 802.1x authentication

    Posted Nov 09, 2017 12:40 PM

    In order for me to have both 802.1x and MAC auth on the port I have to use the web-based instead of authenticator which I do not care for at all. 



  • 5.  RE: ClearPass 802.1x authentication

    EMPLOYEE
    Posted Nov 09, 2017 12:47 PM
    Not sure I understand what you're saying. If you follow the doc, it will give you a complete colorless port configuration.


  • 6.  RE: ClearPass 802.1x authentication

    MVP
    Posted Nov 09, 2017 12:53 PM

    Do the phones do 802.1X username/password or Certificate authentication? In order to perform the logic of device type, the authentication has to succeed first. That authentication needs to be validated somehow, and after then you can use role mapping or enforcement policy to say "Device Category = VoIP Phone" to then assign a VLAN or dACL (cisco).

     

    If you do MAC-based Authentication, you can do Allow All MAC Auth, and do the same logic. If you have computers connected behind the phones, and your using Cisco, make sure you configure Multihost (forget actual name, it's Multi something)



  • 7.  RE: ClearPass 802.1x authentication

    MVP
    Posted Nov 09, 2017 12:55 PM

    Also, that logic is dependent upon the fingerprinting. I would suggest setting up some type of IP helper pointing toward ClearPass or other way of fingerprinting to ensure when new phones are added, they are identified as VoIP as well.



  • 8.  RE: ClearPass 802.1x authentication

    EMPLOYEE
    Posted Nov 09, 2017 12:58 PM
    Yep. All that is covered in the doc 😉


  • 9.  RE: ClearPass 802.1x authentication

    Posted Nov 09, 2017 01:29 PM

    So am I reading this write that I have to setup roles on the switches with different policies for this to work properly?



  • 10.  RE: ClearPass 802.1x authentication

    EMPLOYEE
    Posted Nov 09, 2017 01:31 PM
    Not necessarily, but roles are the recommended way to deploy colorless ports and that's what the docs cover.


  • 11.  RE: ClearPass 802.1x authentication

    MVP
    Posted Nov 09, 2017 01:34 PM

    Assuming your working with Aruba switches? 2900 series or 3800 series?



  • 12.  RE: ClearPass 802.1x authentication

    Posted Nov 09, 2017 01:35 PM

    No these are Aruba 2530's 



  • 13.  RE: ClearPass 802.1x authentication

    Posted Nov 09, 2017 01:42 PM

    This is my issue and error that I am getting when trying to enable MAC and authenticator access on the same port.  

     

    access.JPG



  • 14.  RE: ClearPass 802.1x authentication

    EMPLOYEE
    Posted Nov 09, 2017 01:44 PM
    Re-run those config commands in the reverse error.


  • 15.  RE: ClearPass 802.1x authentication

    Posted Nov 09, 2017 01:47 PM

    Same result. 



  • 16.  RE: ClearPass 802.1x authentication

    EMPLOYEE
    Posted Nov 09, 2017 01:50 PM
    Hm. Best to work with your partner or TAC. It's a validated config so something must be up with your switch.


  • 17.  RE: ClearPass 802.1x authentication

    Posted Nov 09, 2017 01:55 PM

    Seems odd since I tried this on the Customers 2530 and now in my test lab 2530 with the same error and result. 



  • 18.  RE: ClearPass 802.1x authentication

    MVP
    Posted Nov 09, 2017 01:59 PM

    Just curious - what version is running on the switch?



  • 19.  RE: ClearPass 802.1x authentication

    Posted Nov 09, 2017 02:00 PM

    SW2(config)# sho ver

    Image stamp: /ws/swbuildm/rel_ukiah_qaoff/code/build/lakes(swbuildm_rel_ukiah_qaoff_rel_ukiah)
    Oct 12 2017 22:43:52
    YA.16.04.0009
    723
    Boot Image: Primary

    Boot ROM Version: YA.15.20



  • 20.  RE: ClearPass 802.1x authentication

    Posted Nov 09, 2017 02:16 PM

    If this error wasnt occuring I would be able to have this done already :) 

     

     



  • 21.  RE: ClearPass 802.1x authentication

    Posted May 22, 2018 07:17 PM

    Hi,

     

    Any updates about this issue? One of our customers mentioned same issue and we opened a case but case has not been owned yet.

     

    Thank you.



  • 22.  RE: ClearPass 802.1x authentication

    Posted Mar 14, 2019 09:59 AM

    Any update? I am running into the same issue. I am using Aruba 2930 switches, and it will not allow me to do a combination of MAC auth and 802.1x. This is a big problem for us and our design. Hopefully you were able to get some good information!