Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

MC 7200 Authentication Server

This thread has been viewed 0 times
  • 1.  MC 7200 Authentication Server

    Posted Apr 22, 2016 11:48 PM

    Hello,


    In case of Internal AAA Server is used on the Mobility Controller MC 7200, in this case:

    > Can we assign a group of AP's to be Authenticators for this internal MC Authentication Server? - And, another group of AP's, the MC will forward their Radius messages to external Radius Server?

    > How can this be done?


    Another questions please, in case of internl Auth Server by the MC 7200, what are the requirements on the Client UE? Does he need to support for example some kind of EAP?

     

    Thanks.



  • 2.  RE: MC 7200 Authentication Server

    EMPLOYEE
    Posted Apr 22, 2016 11:50 PM
    Yes. Authentication is defined in each VAP. Each AP group can have different VAPs.

    You should consider using a RADIUS server for all authentication instead of the internal database.


  • 3.  RE: MC 7200 Authentication Server

    Posted Apr 23, 2016 12:00 AM

    What are the requirements on the Cleints UE's in case of Internal Auth Server?



  • 4.  RE: MC 7200 Authentication Server
    Best Answer

    EMPLOYEE
    Posted Apr 23, 2016 12:04 AM
    Are you doing cert based auth or username/password?

    EAP-TLS, EAP-PEAP/MSCHAPv2, and EAP-PEAP/GTC are supported.


  • 5.  RE: MC 7200 Authentication Server

    Posted Apr 23, 2016 12:11 AM

    Username/Password only



  • 6.  RE: MC 7200 Authentication Server

    EMPLOYEE
    Posted Apr 23, 2016 04:08 AM

    The EAP method most often used is EAP-PEAP/MSCHAPv2 because all clients support it.

     

    Like T Cappalli says, you should really not bother with the intenal radius server;  you should use an external one for maximum flexibility.