Security

last person joined: 2 days ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Using ClearPass for IDP AAA with OTP via email/sms?

This thread has been viewed 7 times
  • 1.  Using ClearPass for IDP AAA with OTP via email/sms?

    Posted Nov 05, 2015 02:08 PM

    Hello,

     

      We're attempting to add an additional layer of security to certain resources that are authenticated/authorized through our SAML2 IDP (NetIQ Access Manager).  One of the auth method available is RADIUS, so we're wondering if ClearPass can help us with the functionality we want without building/buying another RADIUS server.  

     

      The functionality we want to add is the ability to use SMS and/or email (preferably user-chosen at login time) to send an OTP token as a second layer of authentication (after user/pass).  Assuming we provide the SMS and email gateways, is this something CP can handle and has anyone ever done such a thing?  Any reason I could be missing why we wouldn't want to do this using CP?



  • 2.  RE: Using ClearPass for IDP AAA with OTP via email/sms?
    Best Answer

    Posted Nov 05, 2015 08:07 PM
      |   view attached

    I think you can absolutely use ClearPass to do this.  We have the ability to send custom HTTP messages as the result of an authentication event (in your case using radius).  You should be able to use this to send a custom payload to your gateway to trigger the OTP.

     

    If you have not checked out our ClearPass Exchange page then that is a good place to start.  Hopeully it gives you a feel for how to construct the outbound messages depening on what your gateway accepts.  Tehnote attached to this post

     

    http://community.arubanetworks.com/t5/ClearPass-Exchange-Recipes/tkbc-p/clearpass-recipes

     

    As a side note ClearPass itself supports SAML2.0 for access to the admin, guest, insight or onboard login pages and you can levearge our skin technology for SSO portals.

     

    Let us know how you get on