Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Critical authentication

This thread has been viewed 48 times
  • 1.  Critical authentication

    Posted May 20, 2021 06:09 AM
    Hello,

    I'd like to deploy a critical authentication feature to HPE and Aruba (ArubaOS) switches. I've been checking the configuration guide and I've found only one way to perform it using the roles configured in the switch:

    1. Assign a user-role containing untagged VLAN as critical-role using the command aaa port-access <port> critical-auth user-role <ROLE-NAME>

    Using this feature, I understand that devices connected to the ports configured with this command, are going to get access to the network and they'll receive the vlan inside the role configured always that CPPM server be unreachable.

    I've seen that Aruba with AOS-CX switches can perform this feature with more options:

    aaa authentication port-access [critical-role|preauth-role|reject-role|auth-role] <ROLE-NAME>
    critical-role

    Specifies the role that is applied when the RADIUS server is unreachable for authentication or when there is a request timeout.

    preauth-role

    Specifies the role that is applied when authentication is still in progress.

    reject-role

    Specifies the role that is applied when authentication has failed.

    auth-role

    Specifies the role that is applied to authenticated clients when a specific role is not assigned in the RADIUS server.

    <ROLE-NAME>

    Specifies the role name.

    I'd like to deploy this feature when CPPM servers will be unreachable and in specific switches, when the authentication process will fail. With ArubaCX OS I could make that using the "reject-role" parameter. Do you know a procedure to perform this feature with ArubaOS and HPE switches?

    Thanks in advance.





    ------------------------------
    tech_sec
    ------------------------------


  • 2.  RE: Critical authentication

    MVP GURU
    Posted May 20, 2021 04:01 PM
    Hi,

    Critical and open authentication is available on ArubaOS switch

    ------------------------------
    PowerArubaSW : Powershell Module to use Aruba Switch API for Vlan, VlanPorts, LACP, LLDP...

    PowerArubaCP: Powershell Module to use ClearPass API (create NAD, Guest...)

    PowerArubaCX: Powershell Module to use ArubaCX API (get interface/vlan/ports info)..

    ACEP / ACMX #107 / ACDX #1281
    ------------------------------



  • 3.  RE: Critical authentication

    Posted May 26, 2021 07:02 PM
    Thanks!!!

    ------------------------------
    tech_sec
    ------------------------------



  • 4.  RE: Critical authentication
    Best Answer

    Posted May 20, 2021 04:19 PM
    Hi

    On ArubaOS-Switch you have two options:
    - Open Authentication - access before authentication
    - Critical Authentication - access when Radius is not reachable

    Unfortunately, you can only use open authentication for mac-auth.

    There is one more options, you can use "unauth-vid", which is similar for Open Authentication. 

    You can read more from docs, page 453 - https://support.hpe.com/hpesc/public/docDisplay?docId=a00112863en_us
    About "unauth-vid" check page 639

    Regards


    ------------------------------
    Piotr Filip

    ACEX#41/ACCX/ACDX/ACMX/CWNA/CWSP
    ------------------------------



  • 5.  RE: Critical authentication

    Posted May 21, 2021 02:54 AM
      |   view attached
    I looked at this a couple of years ago, it might have changed since then.
    Have a look at the attached presentation slide 115-126

    ------------------------------
    Derin Mellor
    ------------------------------

    Attachment(s)



  • 6.  RE: Critical authentication

    Posted May 26, 2021 07:03 PM
    Thank you for this presentation Derin, I can get a lot of information from it.

    ------------------------------
    tech_sec
    ------------------------------



  • 7.  RE: Critical authentication

    Posted May 26, 2021 07:02 PM
    Thank you Piotr

    ------------------------------
    tech_sec
    ------------------------------



  • 8.  RE: Critical authentication

    Posted Jun 01, 2021 08:31 PM
    Thank you Piotras, 

    about the unauth-vid, can it be only used with Mac-auth?

    Thanks in advance.

    ------------------------------
    tech_sec
    ------------------------------