Security

last person joined: 11 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Why in this day and age does Aruba only allow you to enter an IP address for RADIUS/LDAP

This thread has been viewed 1 times
  • 1.  Why in this day and age does Aruba only allow you to enter an IP address for RADIUS/LDAP

    Posted Jun 13, 2018 10:34 AM

    It's 2018 and Aruba still only lets you enter one single IP address for a RADIUS or LDAP server. Why is my question.

     

    This is bad because it is very limiting. Businesses and corporations need to ensure there is redundancy. Using round-robin DNS is a very old form of redundancy and used quite a lot when it comes to authentication. Can't use it in Aruba though. You can only enter one single IP address for an authentication server. 



  • 2.  RE: Why in this day and age does Aruba only allow you to enter an IP address for RADIUS/LDAP

    EMPLOYEE
    Posted Jun 13, 2018 10:36 AM
    Which product are you referring to? ArubaOS allows IP or FQDN.

    Also keep in mind that some functions of RADIUS like Dynamic Authorization require configuration by IP.


  • 3.  RE: Why in this day and age does Aruba only allow you to enter an IP address for RADIUS/LDAP

    Posted Jun 13, 2018 10:38 AM

    We're on IAPs. It only allows us to configure an IP address. Won't even let you type in a hostname.

     

     



  • 4.  RE: Why in this day and age does Aruba only allow you to enter an IP address for RADIUS/LDAP

    EMPLOYEE
    Posted Jun 13, 2018 10:41 AM
    Please submit a feature request. Most environments use IP address regardless.


  • 5.  RE: Why in this day and age does Aruba only allow you to enter an IP address for RADIUS/LDAP

    Posted Jun 13, 2018 10:43 AM

    Most environments != all environments though. With a lot of people moving things like RADIUS/LDAP to the cloud, it's less and less using just a single IP address.



  • 6.  RE: Why in this day and age does Aruba only allow you to enter an IP address for RADIUS/LDAP

    EMPLOYEE
    Posted Jun 13, 2018 10:45 AM
    RADIUS Dynamic Authorization still requires an IP address. That is the main reason.


  • 7.  RE: Why in this day and age does Aruba only allow you to enter an IP address for RADIUS/LDAP

    Posted Jun 13, 2018 10:48 AM

    That doesn't explain LDAP though.



  • 8.  RE: Why in this day and age does Aruba only allow you to enter an IP address for RADIUS/LDAP

    EMPLOYEE
    Posted Jun 13, 2018 10:53 AM
    I would recommend you discuss with your Aruba account team.


    A side question. Do you really want APs talking directly to your LDAP infrastructure? A RADIUS server is always recommended.


  • 9.  RE: Why in this day and age does Aruba only allow you to enter an IP address for RADIUS/LDAP

    Posted Jun 13, 2018 10:58 AM

    Why would Aruba offer it and then not recommend it haha. That's backwards.



  • 10.  RE: Why in this day and age does Aruba only allow you to enter an IP address for RADIUS/LDAP

    EMPLOYEE
    Posted Jun 13, 2018 11:14 AM
    We offer many things for flexibility. Doesn't mean it's a best practice.


  • 11.  RE: Why in this day and age does Aruba only allow you to enter an IP address for RADIUS/LDAP

    Posted Jun 13, 2018 11:18 AM

    I've not really seen a reason why RADIUS is "best practice" over using LDAP. What is wrong with using LDAP for WPA2-Enterprise? 



  • 12.  RE: Why in this day and age does Aruba only allow you to enter an IP address for RADIUS/LDAP

    EMPLOYEE
    Posted Jun 13, 2018 11:24 AM
    Allowing edge network infrastructure to access user credentials is never a good thing. To be clear, LDAP is still used with a RADIUS server.


  • 13.  RE: Why in this day and age does Aruba only allow you to enter an IP address for RADIUS/LDAP

    Posted Jun 13, 2018 11:31 AM

    So it's recommended to use an unencrypted protocol still in 2018?



  • 14.  RE: Why in this day and age does Aruba only allow you to enter an IP address for RADIUS/LDAP

    EMPLOYEE
    Posted Jun 13, 2018 11:38 AM
    The EAP method you choose dictates that. The best practice recommendation is EAP-TLS with a RADIUS server. This is industry standard.