Wireless Access

last person joined: 18 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Controller integration with OneLogin

This thread has been viewed 2 times
  • 1.  Controller integration with OneLogin

    Posted Oct 21, 2015 02:36 PM

    Hi Forum,

     

    I don't have any experience with OneLogin and want to ask if the aruba controller is able to integrate with OneLogin as a Radius or auth server? without ClearPass in the play.

     

    Thanks,



  • 2.  RE: Controller integration with OneLogin

    EMPLOYEE
    Posted Oct 21, 2015 02:58 PM
    If it is a normal RADIUS server, yes.


  • 3.  RE: Controller integration with OneLogin

    Posted Oct 21, 2015 03:01 PM

    Thanks Tim. not sure what you mean by "normal".

     

    it is a radius server that is a cloud based.



  • 4.  RE: Controller integration with OneLogin

    EMPLOYEE
    Posted Oct 21, 2015 03:02 PM
    Yes should work then. Question is do you really want your management
    authentication in the cloud? :)


  • 5.  RE: Controller integration with OneLogin

    Posted Jan 12, 2016 11:51 PM

    were you able to get it working?



  • 6.  RE: Controller integration with OneLogin

    Posted Apr 16, 2016 04:12 PM

    Tim, how can I do that?

    Looks like AIs support only PEAP-GTC and PEAP-MSCHAPv2, but onelogin supports only PAP or EAP-TTLS/PAP

    Are there any possibilities to get EAP-TTLS/PAP working on AIs?



  • 7.  RE: Controller integration with OneLogin

    EMPLOYEE
    Posted Apr 16, 2016 04:29 PM
    You need to use a RADIUS server. The APs are EAP-agnostic.


  • 8.  RE: Controller integration with OneLogin

    Posted Apr 16, 2016 04:33 PM

    OneLogin have Radius server onboard, but it only supports PAP and EAP-TTLS/PAP => doesn't work with AIs

    https://onelogin.zendesk.com/hc/en-us/articles/202361670



  • 9.  RE: Controller integration with OneLogin

    EMPLOYEE
    Posted Apr 16, 2016 04:35 PM
    Instant is EAP-agnostic, it should work if you define OneLogin as the radius server.


  • 10.  RE: Controller integration with OneLogin

    Posted Apr 16, 2016 04:38 PM


  • 11.  RE: Controller integration with OneLogin

    EMPLOYEE
    Posted Apr 16, 2016 04:52 PM
    Most devices do not support EAP-TTLS without a configuration profile or custom supplicant. What type of device are you testing with?


  • 12.  RE: Controller integration with OneLogin

    Posted Apr 17, 2016 11:10 AM

    Tim, that means protocol is defined on client? Cool, I'll check on Monday



  • 13.  RE: Controller integration with OneLogin

    Posted Apr 18, 2016 06:17 PM

    Tim, I checked it today, everything is working perfect.

    For Mac OS X I used Apple Configurator 2 to create profile for EAP-TTLS/PAP, then it can be easily applied to all laptops.

    Not tried, but it should work out of the box with Linux, Android and modern versions of Windows (8+).

    Thank you very much!