Security

 View Only
last person joined: 3 days ago 

Enterprise security using ClearPass Policy Management, ClearPass Security Exchange, IntroSpect, VIA, 360 Security Exchange, Extensions and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

VIA VPN radius flags

This thread has been viewed 11 times
  • 1.  VIA VPN radius flags

    Posted Sep 14, 2022 02:58 PM
    Attempting to add a new service to Clearpass that uses Duo MFA. In the short term, goal is to target a specific VPN profile. But I'm having trouble figuring out what RADIUS rules to implement to sort VIA VPN profile authentication attempts as they come in.

    There are no Aruba:VIA radius attributes I can find, and I'm not sure what IETF attribute would apply, nor how I'd configure it so the profiles are unique controller-side.

    WiFi is easy: just target the SSID. The VPN is giving me more difficulty. Annoyingly, I can find plenty of guides for doing it with a Cisco ASA as my VPN concentrator.


  • 2.  RE: VIA VPN radius flags

    EMPLOYEE
    Posted Sep 15, 2022 06:13 AM
    see if this guide helps you
    https://www.flomain.de/2020/06/aruba-via-vpn-with-ikev2/

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------



  • 3.  RE: VIA VPN radius flags

    EMPLOYEE
    Posted Sep 15, 2022 07:47 AM
    If there are no differentiating attributes in the RADIUS request, I think you can select authentication servers per profile, and in the authentication server set the NAS-ID, which you can use to select the service or use in your evaluation/enforcement.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------