Security

 View Only
  • 1.  CPPM Secure Admin-Logon with MFA

    Posted Jun 15, 2025 06:57 AM

    Hello everyone,

    I've searched over the internet and also in this forum, but I haven't found nothing similar to my scenario...

    We are using MS Authenticator as second Factor, now we want to secure admin access to CPPM with cred+pass and OTP,

    Recently we have had a MFA service on prem solution - we've used there Token Server as Authentication Source and everything was OK.

    This won't work with MS Auth, and if so, we don't want to use it to provide only OTP for authentication (recent solution used private PIN which was combined with OTP).

    We are using some 3rd party appliances which do allow MFA with MS Authenticator but with a help of NPS which is connected to Entra.

    As long as I'm getting it right, ClearPass logons are listed as Auth-Type TACACS+, which NPS doesn't use. Moreover RADIUS Proxies are only

    allowed on Service Auth-Type RADIUS.
    Does anyone has such a setup and could provide me some hints on getting this done? 


    Thanks in advance and best Regards!



    ------------------------------
    gst
    ------------------------------


  • 2.  RE: CPPM Secure Admin-Logon with MFA
    Best Answer

    Posted Jun 16, 2025 09:19 AM

    What probably works best is to integrate through SAML SSO to your Identity/Authentication platform and configure the MFA there similar to other applications that you may have. That avoids a point solution for ClearPass:

    Policy Manager is the ClearPass login....



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: CPPM Secure Admin-Logon with MFA

    Posted Jun 17, 2025 02:14 AM

    Hello Herman,

    Thank you, it makes a lot of sense, I'll try it out and give a feedback.

    Best Regards,

    Grzegorz



    ------------------------------
    gst
    ------------------------------



  • 4.  RE: CPPM Secure Admin-Logon with MFA

    Posted 22 days ago
    Edited by gst 22 days ago

    Hello Herman,

    After crashing my ClearPass on first try (SSO was not disabled properly after test and was applied to Policy Manager, recovery via SSH and "system sso-reset"...) I've finally managed to run SSO for Guest and Insight. This was really straightforward! With the SSO Service Template I got a simple Enforcement Profile with SSO-Role = Super Administrator. I would like to tweak SSO Service / Profile so that I can give different privileges to Admin, Support and Compliance similar to Active Directory authorization via group membership. Can I use AD or Entra for that? 

    Best Regards,



    ------------------------------
    gst
    ------------------------------



  • 5.  RE: CPPM Secure Admin-Logon with MFA

    Posted 22 days ago

    Using AD or Entra for authorization is certainly possible. Just add Entra or AD as AuthZ source to the service and built the Role Mapping to assign the required permissions. The SAML username will be used to do the lookup in AD or Entra. Other option is use the SAML claims to assign the right level.



    ------------------------------
    Willem Bargeman
    Systems Engineer Aruba
    ACEX #125
    ------------------------------



  • 6.  RE: CPPM Secure Admin-Logon with MFA

    Posted 22 days ago
    Edited by gst 22 days ago

    Hello Willem, hello Herman,

    I think we might get into some trouble using AD because we use UPN in Entra and Usernames in AD. I think I give it a try with Entra claims. 
    Now I got another issue with HTTPS certificate... In SSO configuration ClearPass persists to use FQDN combined with our internal domain, this parameter isn't editable from SSO config page. 
    For guest registration purpouse I've set a HTTPS certificate from public CA. Now when I logon on ClearPass I get a certificate warning because I've no certificate for internal FQDN - how to solve this issue?

    Best Regards,

    ------------------------------
    gst
    ------------------------------



  • 7.  RE: CPPM Secure Admin-Logon with MFA

    Posted 22 days ago

    The easiest one will be the EntraID AuthZ source or using the SAML claims. Please note that it is possible to strip domains from the usernames. 

    ClearPass supports one HTTPS certificate per appliance. Best is to use a public sign certificate. You can use the same FQDN for Guest users and MGMT users. Or add an additional SAN to the cert as FQDN for mgmt purposes. However, that one off-course needs to be a public FQDN. 



    ------------------------------
    Willem Bargeman
    Systems Engineer Aruba
    ACEX #125
    ------------------------------