Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass MFA integration using EAP-TLS certificate authentication

This thread has been viewed 3 times
  • 1.  ClearPass MFA integration using EAP-TLS certificate authentication

    Posted Feb 01, 2017 08:09 AM

    Hi, I would like to check whether is it possible to provide MFA integration using EAP-TLS certificate authentication? Is there been any documentation on this? Thank you.



  • 2.  RE: ClearPass MFA integration using EAP-TLS certificate authentication

    Posted Feb 01, 2017 08:12 AM
    Using ClearPass Onboard or using internal PKI ?


  • 3.  RE: ClearPass MFA integration using EAP-TLS certificate authentication

    Posted Feb 01, 2017 08:14 AM

    Thanks for the fast reply! We are using OnBoard.



  • 4.  RE: ClearPass MFA integration using EAP-TLS certificate authentication

    Posted Feb 01, 2017 08:39 AM
    Starting in 6.6.x you can integrate ClearPass Onboard with several MFA options Cloud MFA Providers= DUO , Kasada to name a few and also SMS as part of the Onboarding Captive portal authentication/verification workflow


  • 5.  RE: ClearPass MFA integration using EAP-TLS certificate authentication

    EMPLOYEE
    Posted Feb 01, 2017 09:18 AM
    Please explain your scenario further. In most cases, the authentication method is independent of MFA.


  • 6.  RE: ClearPass MFA integration using EAP-TLS certificate authentication

    Posted Feb 02, 2017 10:12 AM

    Is it possible that after EAP-TLS (certificate) authentication, prompt the user to key in another password for 2nd token authentication before the user can be connected to the network? 



  • 7.  RE: ClearPass MFA integration using EAP-TLS certificate authentication

    EMPLOYEE
    Posted Feb 02, 2017 10:16 AM
    Which MFA provider are you using?


  • 8.  RE: ClearPass MFA integration using EAP-TLS certificate authentication

    Posted Feb 02, 2017 10:18 AM

    We would be using RSA as the MFA provider.



  • 9.  RE: ClearPass MFA integration using EAP-TLS certificate authentication

    EMPLOYEE
    Posted Feb 02, 2017 12:35 PM

    Legacy RSA token 2FA unfortunately cannot be used with EAP-TLS as there is no mechanism append the PIN code.



  • 10.  RE: ClearPass MFA integration using EAP-TLS certificate authentication

    Posted Feb 02, 2017 08:34 PM

    Thanks, is there any other MFA provider that can support EAP-TLS integration?