Security

 View Only
Expand all | Collapse all

Adding Greenlake Device Inventory as Authentication Source in Clearpass

This thread has been viewed 41 times
  • 1.  Adding Greenlake Device Inventory as Authentication Source in Clearpass

    Posted Mar 24, 2025 05:38 AM

    Hi,


    we would like to up our security by implementing 802.1X Wired Authentication using CX-Switches and Clearpass 6.12.

    Is there an option to add the Device Inventory of Greenlake as an Authentication Source in Clearpass to use the database to recognize the added APs and Switches and realize a rolemapping based on that?


    I really don't want to authenticate 1300 APs via MacAuth :-D 

    Thanks in advance



  • 2.  RE: Adding Greenlake Device Inventory as Authentication Source in Clearpass

    Posted Mar 24, 2025 07:10 AM

    I don't think this is possible.  Why do you need this though?  Why not use profiling?  Are your APs not connected to trunk ports?




  • 3.  RE: Adding Greenlake Device Inventory as Authentication Source in Clearpass

    Posted Mar 24, 2025 07:30 AM

    Currently they are connected via trunk ports yes. 

    Profiling would work but it would also work for any Aruba AP that joins the network and not only the ones under our administration.




  • 4.  RE: Adding Greenlake Device Inventory as Authentication Source in Clearpass

    Posted Mar 24, 2025 07:34 AM
    Right but you can't perform authentication on trunk ports. 

    You have to use smart port macros or something like that to convert from the initial access state to trunk state. It's rarely worth the overhead imo.





  • 5.  RE: Adding Greenlake Device Inventory as Authentication Source in Clearpass

    Posted Mar 24, 2025 08:00 AM

    I had it working on AOS-S Switches. Not role-based because AOS-S couldn't handle more than one tagged vlan per role but it worked.

    Just as a proof-of-concept I added an AP as a Guest-Device and let Clearpass give back the one untagged and three tagged vlans.

    So an option would be to export the AP-list from central and add it into Clearpass as Guest-devices. But that would lead to manual work everytime we add a new AP.




  • 6.  RE: Adding Greenlake Device Inventory as Authentication Source in Clearpass

    Posted Mar 24, 2025 08:04 AM
    You could maybe automate this somehow with an API? Just remember MAC addresses can always be spoofed as well.






  • 7.  RE: Adding Greenlake Device Inventory as Authentication Source in Clearpass

    Posted Mar 24, 2025 08:15 AM

    Yes that's true but that needs more involvement than buying an AP. 

    I'll have a look at the API on Aruba Central. Maybe I can use a script to pull the information and store it in a local database which I then use as authentication source in Clearpass




  • 8.  RE: Adding Greenlake Device Inventory as Authentication Source in Clearpass

    Posted Mar 24, 2025 12:00 PM

    If you have Activate enabled on your GreenLake workspace then you can still configure the integration between ClearPass and Activate, which will allow ClearPass to pull the devices in the Activate inventory into the ClearPass Endpoints Repository.

    Don't use MAC auth, use EAP-TLS with the AP's device certificate.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 9.  RE: Adding Greenlake Device Inventory as Authentication Source in Clearpass

    Posted Mar 25, 2025 08:05 AM

    We do not have Activate because we are using Aruba Networking Central. Pulling the devices into the Endpoint Repository is exactly what I want to do.

    Sure another way would be to push a private certificate via Central and using EAP-TLS as authentication. Then I wouldn't need the devices in a repository.

    Using the build-in certificate would make it possible to authenticate other Aruba APs.




  • 10.  RE: Adding Greenlake Device Inventory as Authentication Source in Clearpass

    Posted Mar 25, 2025 11:15 AM

    Activate is still an option even with Central, but if you already have Central then you could use the API and a script or Postman collection to pull the inventory from Central and push the information to ClearPass.

    The point was to use EAP-TLS in conjunction with your device import.  EAP-TLS provides the secure authentication method while the import provides authorization to filter on only your devices.

    The "best" solution would be to have the devices enroll a custom certificate using EST which would allow you to authenticate only those devices you control.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 11.  RE: Adding Greenlake Device Inventory as Authentication Source in Clearpass

    Posted Mar 26, 2025 01:48 AM

    I don't think we have access to Activate as we migrated from an AOS 8.6 deployment with VCs and Airwave straight to AOS 10 and Central.

    But yes, what you are saying sounds like the the best option as there seems to be no native interaction possibility between the two. 




  • 12.  RE: Adding Greenlake Device Inventory as Authentication Source in Clearpass

    Posted Mar 27, 2025 05:01 AM

    Support can give you access to Activate (via GreenLake). When you have access ClearPass can pull information from GreenLake / Activate and store the registered devices in the Endpoint repository. 



    ------------------------------
    Willem Bargeman
    Systems Engineer Aruba
    ACEX #125
    ------------------------------



  • 13.  RE: Adding Greenlake Device Inventory as Authentication Source in Clearpass

    Posted Mar 24, 2025 12:01 PM

    Hi !
    If the APs are in Central, I suppose they are Aruba APs.


    Do you not want to enable 802.1x authentication on the downlink of the APs?



    ------------------------------
    CyberSec & Network Engineer - ACCX #1532 - ACMP
    ------------------------------



  • 14.  RE: Adding Greenlake Device Inventory as Authentication Source in Clearpass

    Posted Mar 25, 2025 02:06 AM

    We are not using the downlink of the APs. They are deactivated.

    At the moment we are using eap-tls and MSChap to authenticate our wireless clients.

    But in light of the NIS2-directive we need to up it a little bit.




  • 15.  RE: Adding Greenlake Device Inventory as Authentication Source in Clearpass

    Posted Mar 25, 2025 07:29 AM
    Sorry, translation mistake.
    I would say "AP uplink."

    Wireless clients are authenticated by the AP or MC.
    However, you can authenticate APs on switches to only authorize registered APs and improve security.

    Maybe my understanding is incorrect.


    ------------------------------
    CyberSec & Network Engineer - ACCX #1532 - ACX-NS - APC ClearPass - ACMP
    ------------------------------