Security

 View Only
last person joined: 21 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Okta and 802.1X authentication

This thread has been viewed 52 times
  • 1.  Okta and 802.1X authentication

    Posted Jan 12, 2021 05:04 PM
      |   view attached

    Hi Experts,

    Using Okta for cloud identity provider as shown in this guide ClearPass_Configuration-Guide_Onboard-Cloud-Identity-Providers_v2018-01.pdf it is possible to perform the onboard process of the device using Okta credentials. A certificate will be issued and a network profile will be configured in the device.

    The next step, the device will connect to an SSID with 802.1X EAP-TLS.

    To complete this task a new service on the clearpass needs to be created to authenticate with the EAP-TLS method.
    My question is about which authentication source should I use on this service to successfully authenticate the device.? Onboard Device Repository, Local Endpoint Repository, etc. Any Idea?

    Thank you,




  • 2.  RE: Okta and 802.1X authentication

    MVP EXPERT
    Posted Jan 13, 2021 11:06 AM
    You don't use an Authentication Source.

    ------------------------------
    Tim C
    ------------------------------



  • 3.  RE: Okta and 802.1X authentication

    Posted Jan 13, 2021 11:44 AM
      |   view attached

    For the Onboard pre-auth service, the auth source is not required, but for EAP-TLS authentication using Aruba 802.X Wireless service, it requires me to specify at least one auth source.

    I tried to add some for test and got this message on the access: EAP-TLS: Authentication failure, unknown user. 

    I confirmed in the Clearpass Onboard user/certs and they are there for this user, but auth failed.

    Because of this message, I did double-check what would be the correct auth source. 

     






  • 4.  RE: Okta and 802.1X authentication

    MVP EXPERT
    Posted Jan 13, 2021 11:47 AM
    You need to create a new EAP-TLS method with authorization disabled.

    ------------------------------
    Tim C
    ------------------------------



  • 5.  RE: Okta and 802.1X authentication

    Posted Jan 13, 2021 11:51 AM
    Thank you. I will test and post the results here.





  • 6.  RE: Okta and 802.1X authentication

    Posted Jan 14, 2021 10:31 AM
    Thanks a lot Tim.
    The authentication worked with a new EAP-TLS method with authorization disabled.