Security

 View Only
  • 1.  Clearpass mixing EAP-TLS and TEAP auth methods under the same service

    Posted Sep 16, 2024 02:21 AM

    Is there a way to have both authentication methods enabled for the same service? I tried adding both but I can't seem to make it work. When both auth methods are enabled, TEAP clients can't authenticate. Clearpass gets presented with the wrong credentials, but as soon as I remove EAP-TLS, it starts working. See screenshot below

    Both EAP-TLS and TEAP enabled

    Just TEAP

    I thought of creating a separate service just for TEAP clients using the service rules below but now my client can't even connect to the network. I don't even get a hit for this connection attempt in the access tracker logs.

    Error I get in Windows for the TEAP client



  • 2.  RE: Clearpass mixing EAP-TLS and TEAP auth methods under the same service

    Posted Sep 16, 2024 11:29 AM

    Yeah it's certainly possible.  You just need to write policies in a way that will match properly depending on your specific use-case.




  • 3.  RE: Clearpass mixing EAP-TLS and TEAP auth methods under the same service

    Posted Sep 16, 2024 01:46 PM

    Do you know why Clearpass is getting the wrong credentials when I have both enabled? On my first screenshot, it only shows one TEAP method, which then fails the session.

    This is my current Roles Rules:

    And this is my current Service Rules




  • 4.  RE: Clearpass mixing EAP-TLS and TEAP auth methods under the same service
    Best Answer

    Posted Sep 17, 2024 01:58 PM

    I was able to fix this thanks to Zednick from reddit by creating a separate service where the first service has the following rule:
    Radius:IETF User-Name BELONGS_TO anonymous,teap

    And the other service only checks for the SSID.