Security

last person joined: 9 hours ago 

Enterprise security using ClearPass Policy Management, ClearPass Security Exchange, IntroSpect, VIA, 360 Security Exchange, Extensions and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Does Clearpass support Radius Forwarding?

This thread has been viewed 1 times
  • 1.  Does Clearpass support Radius Forwarding?

    Posted Aug 22, 2014 07:33 AM

    Simple question but have not found a solid answer anywhere?

    Does Clearpass support Radius Forwarding with Instant Access Point?

    ClearPass Policy Manager 6.4.0.66263 on CP-VA-5K platform.



  • 2.  RE: Does Clearpass support Radius Forwarding?

    Posted Aug 22, 2014 07:34 AM
    Can you explain a bit more? What is radius forwarding?


  • 3.  RE: Does Clearpass support Radius Forwarding?

    Posted Aug 22, 2014 08:57 AM

    This function been around since Window Server 2003 NPS, however I'm struggling to find this in the Clearpass Policy Manager.

     

    The Clearpass Policy Manager is the Radius server.

     

     

    RADIUS Access-Request messages are processed or forwarded by NPS only if the settings of the incoming message match at least one of the connection request policies configured on the NPS server.

     

    If the policy settings match and the policy requires that the NPS server process the message, NPS acts as a RADIUS server, authenticating and authorizing the connection request.

     

    If the policy settings match and the policy requires that the NPS server forwards the message, NPS acts as a RADIUS proxy and forwards the connection request to a remote RADIUS server for processing.

     

    - explanation taken from http://msdn.microsoft.com/en-us/library/cc753603.aspx

     

     

     



  • 4.  RE: Does Clearpass support Radius Forwarding?

    Posted Aug 22, 2014 09:00 AM

    Yes you would just use the RADIUS proxy feature.

     

    - Setup a proxy target:

       Configuration > Network > Proxy Target

     

    nps-proxy-1.JPG

     

    - Create a new RADIUS proxy service that matches the appropriate attributes or if you just want things to fall through to this, setup the basic rules like NAS-Port-Type and Service-Type and then put the service at the bottom of your 1X services.

       

    radius-proxy-service.JPG



  • 5.  RE: Does Clearpass support Radius Forwarding?

    Posted Aug 22, 2014 09:07 AM
      |   view attached

    This is what i initially presumed, however adding the Proxy Target, then adding a new RADIUS proxy service did not work.

     

    If you don't mind, could you point out what we are missing?

     

    I know the Proxy Target works correctly, as we have this option enabled using the Microsoft NPS previously.



  • 6.  RE: Does Clearpass support Radius Forwarding?

    Posted Aug 22, 2014 09:10 AM

    Are you seeing anything hit the service in Access Tracker?



  • 7.  RE: Does Clearpass support Radius Forwarding?

    Posted Aug 22, 2014 09:17 AM

    Just added a few service rules to match the Aruba-Essid-Name. I can see the following errors:

     

    Error Code:    208
    Error Category:    Authentication failure
    Error Message:    No response from home server

    Is the Radius Proxy service suppose to have the Authorization option enabled or disabled?



  • 8.  RE: Does Clearpass support Radius Forwarding?

    Posted Aug 22, 2014 09:19 AM

    You only need it if you are making decision in your enforcement policy with attributes from an authorization source. Since you have an allow all, you don't need it.

     

    That error is saying that the NPS server did not respond. Can you check the NPS server event log for any errors?

     



  • 9.  RE: Does Clearpass support Radius Forwarding?

    Posted Aug 22, 2014 09:23 AM

    Thanks for the fast replies so far.

     

    I had the option to allow all for testing purposes, but have now tested this with one of our live policies without luck - same error.

     

    The other end, it is suppose to be recieve the accounting forwarded packets but nothing recieved.



  • 10.  RE: Does Clearpass support Radius Forwarding?

    Posted Aug 22, 2014 08:54 AM
    If this is radius proxy then yes this is supported regardless of device type