Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass with AD using Cert

This thread has been viewed 1 times
  • 1.  Clearpass with AD using Cert

    Posted Jun 13, 2018 02:54 PM

    Good day Team!

     

    I am kind of new with the clearpass and AD. I have a question. 

     

    I have been trying to authenticate a user with an AD using certificates but I keep getting a message that the user is not found in the AD. 

     

    I have been changing the CN and the OU to try to catch a match betwwen my machine and Active directory using Clearpass. I believe that the configuration on the Clearpass is wrong. 

     

    I want to ask you guys a couple of questions. 

     

     

    I attached the configuration of the clearpass and the attributes as well. I want to know if that base DN is the directory that is going to be used on on the AD to look for the customer. And on the second picture, I wanna ask if that is set by default or manually? 

     

    One more question: How do I specify an "any" expresion on the OU field. I want it to know that it has to look in all OUs configured on the AD. The expresion that comes to my mind is "*"

     

    Thanks !

     

     

     



  • 2.  RE: Clearpass with AD using Cert

    EMPLOYEE
    Posted Jun 13, 2018 03:16 PM

    What is the format of the username shown in access tracker? (Authentication:Full-Username)



  • 3.  RE: Clearpass with AD using Cert

    Posted Jun 13, 2018 03:53 PM

    Thank you for your reply!

     

    here is the username: UNAD\aron.gutierrez



  • 4.  RE: Clearpass with AD using Cert

    EMPLOYEE
    Posted Jun 13, 2018 03:55 PM
    Do you have username stripping enabled in your service? This is required for legacy down level logon name username formats.


  • 5.  RE: Clearpass with AD using Cert

    Posted Jun 13, 2018 04:38 PM

    Hello! 

     

    No, its not enabled. I am looking into this right now. 

     

     



  • 6.  RE: Clearpass with AD using Cert

    Posted Jun 13, 2018 04:44 PM
      |   view attached

    I enabled the feature but it keep saying that the full username is UNAD\aron.gutierrez. 



  • 7.  RE: Clearpass with AD using Cert

    EMPLOYEE
    Posted Jun 13, 2018 04:45 PM
    Is it still failing?


  • 8.  RE: Clearpass with AD using Cert

    Posted Jun 13, 2018 04:48 PM

    Yes Sir, it is still failing 



  • 9.  RE: Clearpass with AD using Cert

    EMPLOYEE
    Posted Jun 13, 2018 04:51 PM
    Please post a screenshot of the strip rule.


  • 10.  RE: Clearpass with AD using Cert

    Posted Jun 13, 2018 04:54 PM
      |   view attached

    Sure! 

     

    Here is the screenshot



  • 11.  RE: Clearpass with AD using Cert

    EMPLOYEE
    Posted Jun 14, 2018 07:08 AM
    That looks correct. Please work with Aruba TAC.


  • 12.  RE: Clearpass with AD using Cert

    Posted Jun 18, 2018 11:48 AM

    Will do! 

     

    Thanks for the help!