Security

Reply
Occasional Contributor II
Posts: 19
Registered: ‎08-24-2011

Instant AP Sending either hostname OR username to ClearPass

Instant AP Cluster is sending either username or hostname for AAA on ClearPass.  Can we restrict the IAP cluster to only send the username, and CPPM to only accept the username authentication?

Guru Elite
Posts: 8,740
Registered: ‎09-08-2010

Re: Instant AP Sending either hostname OR username to ClearPass

What type of authentication are you using?

Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Occasional Contributor II
Posts: 19
Registered: ‎08-24-2011

Re: Instant AP Sending either hostname OR username to ClearPass

OnBoard, so first EAP-PEAP, then EAP-TLS.  Sometimes a user authenticates with one (machine or user), then it will send the other, failing and starting the process again.

 

Guru Elite
Posts: 8,740
Registered: ‎09-08-2010

Re: Instant AP Sending either hostname OR username to ClearPass

The reflected username will be dependent on how the device is
authenticating.



If it machine authenticates, it will show the FQHN. If the user
authenticates, it will show the username.



If you want the device to only machine authenticate, you need to configure
the clients manually, use group policy, or use something like quickconnect.



Are you Onboarding personal or corporate devices?

Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Occasional Contributor II
Posts: 19
Registered: ‎08-24-2011

Re: Instant AP Sending either hostname OR username to ClearPass

OnBoard with both corporate and personal devices.

 

I have also enabled MAC Fail-through as a possibility as well, both not "Enforce MAC Auth".

 

 

Guru Elite
Posts: 8,740
Registered: ‎09-08-2010

Re: Instant AP Sending either hostname OR username to ClearPass

The clients would need to be configured for user authentication or you would
have to use dual-SSID onboard.

Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Search Airheads
Showing results for 
Search instead for 
Did you mean: