Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Onboard wired devices

This thread has been viewed 3 times
  • 1.  Onboard wired devices

    Posted Mar 02, 2018 04:23 AM

    Hi,

     

    I'm having difficulty to come up with a solution for onboarding wired devices (mostly Windows 10 hosts). One of the common way is to first authenticate them with PEAP, and then let ClearPass return the URL for the switch to redirect users to onboard page. But my environment uses Azure AD and we don't want to join ClearPass to this AD, which makes PEAP-MSCHAPv2 isn't possible. 

     

    So, is there any other way to automatically redirect wired devices to onboard page, and after they've been provisioned we'll let them authenticate with EAP-TLS?

     

    Any ideas are greatly appreciated.

     

    Regards,



  • 2.  RE: Onboard wired devices

    EMPLOYEE
    Posted Mar 02, 2018 04:32 AM

    Hi,

     

    as you have mentined you don't want to join CP to Azure AD, so you really are limiting your options, as you still need a way to authenticated the devices prior to onboarding.

     

    an option could be wired enforcement with captive portal then use SAML SSO to authenticate the user to ADFS (or another SAML provider).



  • 3.  RE: Onboard wired devices

    Posted Mar 02, 2018 05:01 AM

    Hi matthew,

     

    I'm using ArubaOS switch, and I see that it has the option to specify multiple authentication methods on the port (802.1X, MAC auth, captive portal). But if we set 802.1X first and then captive portal, the users would have to fail 802.1X before being able to fallback to captive portal, which is not very good in terms of user experience. And if we set captive portal first, they might be redirected every time the port comes up, and not being able to authenticate by EAP-TLS. 

     

    That's what I understand about ArubaOS switch's behavior, and I'm afraid it may not work that way. Am I missing something?

     

    Regards,



  • 4.  RE: Onboard wired devices

    EMPLOYEE
    Posted Mar 02, 2018 05:47 AM

    yes the user would fail auth, but as you are not wanting to join AD your options are very limited.



  • 5.  RE: Onboard wired devices

    Posted Mar 02, 2018 08:06 AM




    Thank you

    Victor Fabian

    Pardon typos sent from Mobile


  • 6.  RE: Onboard wired devices

    EMPLOYEE
    Posted Mar 02, 2018 08:14 AM
    Simply set up a wired captive portal workflow to take the user through the process.


  • 7.  RE: Onboard wired devices

    Posted Mar 03, 2018 07:22 AM

    Hi Tim,

     

    I think for that to work we need to configure both 802.1X and captive portal on the switch port, with captive portal as the fallback. And the user would have to fail 802.1X first before captive portal and the onboard process get applied. Correct?

     

     



  • 8.  RE: Onboard wired devices

    EMPLOYEE
    Posted Mar 03, 2018 09:32 AM
    Yes. Please look at the ClearPass Solution Guide for Wired Policy Enforcement.