Cloud Managed Networks

 View Only
Expand all | Collapse all

instant managed with aruba central authenticated with Azure AD

This thread has been viewed 43 times
  • 1.  instant managed with aruba central authenticated with Azure AD

    Posted Apr 01, 2023 11:45 AM

    Hello
    i have 2 questions
    First question
    It is possible to authenticate aruba instant managed with aruba central agains the azure AD? i remenber that you needed the clearpass before but i saw that it seems its possible doing this just with Aruba central and the clearpass does not seems to be needed 

    If i use a controller based solution but with aruba central it is possible to authenticate with azure ad without clearpass?






  • 2.  RE: instant managed with aruba central authenticated with Azure AD

    Posted Apr 01, 2023 11:52 AM
    With Aruba Central you can do Cloud Auth to Azure AD without ClesrPass.

    https://youtu.be/MdfmWPUEr1A



    ---------------------------------
    Jason
    ---------------------------------





  • 3.  RE: instant managed with aruba central authenticated with Azure AD

    Posted Apr 01, 2023 12:10 PM

    It will work with instant only and with the controller solution?

    How this will work? it will be a L3 authentication with a captive portal? or how exactly works?  or it uses like a onboarding system which it comes with the aruba central license for a WPA enterprise?




  • 4.  RE: instant managed with aruba central authenticated with Azure AD

    Posted Apr 03, 2023 06:44 PM

    Anyone?
    If it works without clearpsass what would be the difference with clearpass and without clearpass

    I saw a video also which it seems it just use instant aps but its on another language with i dont understand

    [How to] Setup Aruba Cloud Authentication with Azure AD - YouTube

    it seems there were some questions about this if you could directly integrate this with instant and the aruba central but there were no asnwer.   Someone asked if you could integrate de mobility controller with azure, but it says you needed clearpass for it.
    Now im not sure if the answer was that because in the question he didnt said anything of having aruba central.   In this case i think you can but that would be with aruba central and with Aruba OS 10 but im not sure
    Does anyone know?
    What is the client expirience? its like this, like an onboarding process?? with a link ? and you dont need clearpass? 




  • 5.  RE: instant managed with aruba central authenticated with Azure AD

    Posted Apr 04, 2023 08:21 AM

    It works with Aruba Central and Azure SSO.  I have been testing at our office and it works well, but you need to push Aruba Onboard to your client machines and then they need to click through a provisioning URL.  I am not sure our users are going to be all that adept at completing that part, so I am working on a script to do that  Here is some good documentation on setting up the Azure SSO part.  If you have experience with app registrations or enterprise apps in Azure it's pretty easy: https://www.arubanetworks.com/techdocs/central/latest/content/nms/policy/ca-azure.htm




  • 6.  RE: instant managed with aruba central authenticated with Azure AD

    Posted Apr 04, 2023 09:22 AM

    Hi, answering your questions (or some):

    It works with Instant only? No, you need Central and AOS10 with Cloud Auth . Or you use Instant with Clearpass
    It works with a controller? No, you will need Clearpass
    With Central you will use the Aruba Onboar app (like Paul mentioned) to install the certificate needed to authenticate the user. The authentication will be EAP-TLS since EAP-PEAP is not supported with Azure AD.

    I hope this helps




  • 7.  RE: instant managed with aruba central authenticated with Azure AD

    Posted Apr 04, 2023 10:38 AM
    Edited by cdelarosa Apr 04, 2023 10:43 AM

    Hello Paul, hello Ulises
    Thank for your answer
    i was looking at the documentation regarding this and i saw this
    Aruba Cloud Authentication and Policy Overview (arubanetworks.com)

    Then i clicked on supported deployment types


    It says something about not being supported for overlay deployment type
    Whats is that? is that the tunnel mode with the aps and the gateway if you have a gateway ap wlan solution? with aos 10?

    It seems that its supported on instant AP that is connected to aruba central with those versions, and with the aruba AP with the 10.4 (which i bealive is referring to gateway + Aruba APs but in that version)




  • 8.  RE: instant managed with aruba central authenticated with Azure AD

    Posted Apr 04, 2023 08:11 PM

    Hello Paul, Ulises
    Today i got an access point to test, so a coworker help me out with the azure AD demo 
    So i configured it, it seems easy to configure, just with aruba instant on 8.10

    i saw that you need to copy and paste a url for everyone, if you have your credentials, it will give you access to download your package so it will configure your wifi.

    Paul you said that you are not sure that your users will like the method of clicking the link and downloading the file, i mean it seems really easy to me or to any user.  Or im missing something that could be troublesome because  ill like to know all the possible issues or things the user migh not like 

    Thanks




  • 9.  RE: instant managed with aruba central authenticated with Azure AD

    Posted Apr 04, 2023 08:19 PM

    That's good news. 

    Answering 1 of the questions: For AOS10 you don´t need a gateway you can do it only with the AP in V10 and managed by Central (it won't work without Central anyway)

    I don't know about the overlay deployment mode, but when I know i'll let you know.

    I think Paul refers to the fact that the users have to do something instead of being transparent for them but let's wait If he was talking about something else.

    I hope this helps




  • 10.  RE: instant managed with aruba central authenticated with Azure AD

    Posted Apr 05, 2023 08:22 AM

    I guess my only issue was pushing it out to over 600 users would result in a lot of support tickets for the helpdesk.  I would like to automate that.  Central does have a REST API that provides some help.  Otherwise it is pretty seamless and I would recommend it over RADIUS any day.




  • 11.  RE: instant managed with aruba central authenticated with Azure AD

    Posted Jul 24, 2023 09:51 PM
    Edited by cdelarosa Jul 24, 2023 09:54 PM

    Hello 

    I was wondering what would happen next year when you need to create the new client secret.

    Doesnt that makes have everyone do the process again of clicking the link?

    I mean not for the configuration of the wireless profile i mean for the certificate  renovation? or there is another method of donig this?

    Do you do this on manage network credentials? There is no way to push the new certificates to the client so the client has to do nothing? and we just need to renew the client secret?

    Can the Network admin manage all the certificates somewhere instead of only having the self service platform?