Security

 View Only
  • 1.  EAP-TLS without onboarding licenses

    Posted Oct 18, 2019 10:02 AM

    Dear Experts, 

     

    One of the customer is exploring the option of using certificate based authentication. Is it possible to do certificate management from Active directory CA (or some other CA) and only do the authentication from Clearpass. If yes, will it still need onboarding licenses?



  • 2.  RE: EAP-TLS without onboarding licenses
    Best Answer

    Posted Oct 18, 2019 10:10 AM
    Yes, won’t need onboard licenses if ClearPass is not acting as the CA



    Thank you

    Victor Fabian

    Pardon typos sent from Mobile


  • 3.  RE: EAP-TLS without onboarding licenses

    Posted Oct 18, 2019 10:38 AM
    Can you also highlight will the process of onboarding client will remain
    the same?

    Like directing them to a webpage and configuring their 802.1x settings via
    quick connect tool?


  • 4.  RE: EAP-TLS without onboarding licenses

    Posted Oct 18, 2019 01:37 PM
    Yes you can use a dual Onboarding workflow and configure the necessary policies to provide access to Onboarding devices vs devices using ADCS issued certificates



    Thank you

    Victor Fabian

    Pardon typos sent from Mobile


  • 5.  RE: EAP-TLS without onboarding licenses

    Posted 16 days ago

    Kindly share the process

    regards

    avanindra




  • 6.  RE: EAP-TLS without onboarding licenses

    Posted 15 days ago

    Thanks

    Please share the steps




  • 7.  RE: EAP-TLS without onboarding licenses

    Posted 6 days ago

    You responded to a very old post that is about different methods of EAP-TLS where if you use Onboard or the ClearPass CA, Onboard licenses are needed, if you deploy certificates fully independent of ClearPass, you don't. What 'steps' are you looking for?

    How to setup EAP-TLS and/or ClearPass Onboard is part of every ClearPass training. Your HPE Aruba partner should have this knowledge.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------