
 View Only
  • 1.  MAB wifi + user AD lookup

    Posted Jun 11, 2020 03:14 AM

    Hello everyone,


    I'm currently a bit stuck here. Our standard wifi users can connect without any problem, based on EAP-TLS. Users have a certificate and thanks to an AD attribute they are directed into a certain vlan. We use CISCO AP's and ISE for them, and for a certain SSID's it's redirected to CPPM for authentication. So far, so good.


    Now for non-standard users (-in our case- Androids, Apple, Linux and others) things seems to be a bit more difficult. I tried to put their MAC addresses into a MAB. But it seems as if those devices cannot to this because they have to choose a security structure (e.g. WPA2 with EAP-TLS)


    What I ideally want is that such users can connect to the wifi, put their AD credentials in and are redirected into their proper VLAN.

    Is what I tried to do the correct way, or do I have to work with the guest portal (because self-registration doesn't seem to do the trick neither)?

    Any suggestions are welcome, and if you have a nice how-to somewhere, that would be great

  • 2.  RE: MAB wifi + user AD lookup

    Posted Jun 11, 2020 07:31 AM
    How is the SSID configured ? Open with Mac Filtering ?
    So the plan is that the user is authenticated via captive portal authentication (after they provide their AD credentials) and then device MAC address is cache for a period of time ?

    Thank you

    Victor Fabian

    Pardon typos sent from Mobile

  • 3.  RE: MAB wifi + user AD lookup

    Posted Jun 12, 2020 03:12 AM

    I tried to use the same SSID as we use for our standard devices (devices with certificates), so with WPA2 enterprise and EAP-TLS.
    I don't really have a plan right now But the goal is to allow certain company owned devices (without certificates) on the network without any time boundaries or other.  I tried to allow them based on their MAC address without captive portal or self-registration and I'm trying to figure out whether this is the right approach or not. 
    We do have the self-registration in place but a lot of our non-standard devices aren't supported, so that is not really a solution.

  • 4.  RE: MAB wifi + user AD lookup

    Posted Jun 12, 2020 06:53 AM
    Do you want to only allow certain devices based on the MAC address but the device needs to perform 802.1X/PEAP?

    Thank you

    Victor Fabian

    Pardon typos sent from Mobile

  • 5.  RE: MAB wifi + user AD lookup

    Posted Jun 12, 2020 07:48 AM

    Yes indeed.
    We are talking about non-managed devices, so we can not put a certificate on them.

    I assume I'll have to create a new SSID with different security settings such as EAP/PEAP?

  • 6.  RE: MAB wifi + user AD lookup
    Best Answer

    Posted Jun 12, 2020 08:47 AM
    You can use the same 802.1X SSID you currently use for your devices using TLS
    Your ClearPass service will need to allow PEAP and defined the Guest Device Repository (GDR) as an authorization source , add those devices to GDR .

    You can create a policy that only allow devices that have been registered in the device registration portal + successful PEAP auth

    Thank you

    Victor Fabian

    Pardon typos sent from Mobile

  • 7.  RE: MAB wifi + user AD lookup

    Posted Jun 12, 2020 09:33 AM

    Ok, I'm following thus far, and configured the service for accepting GDR. But how can I obtain a successful PEAP authentication? Can I link this to a user-password combination in the AD? 

  • 8.  RE: MAB wifi + user AD lookup

    Posted Jun 12, 2020 09:54 AM
    Configure your service to use 802.1X and AD as your authentication source , enable authorization and add AD and GDR as your authorization sources .

    Thank you

    Victor Fabian

    Pardon typos sent from Mobile

  • 9.  RE: MAB wifi + user AD lookup

    Posted Jun 12, 2020 10:08 AM

    I'll try to implement this Monday morning, testusers already left for the weekend.
    Thanks for your inputs!!

  • 10.  RE: MAB wifi + user AD lookup

    Posted Jun 15, 2020 05:56 AM

    Hi Victor,


    That worked! Thanks for your help.