Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all
This thread has been viewed 25 times
  • 1.  CPPM MFA

    Posted Oct 18, 2019 06:51 AM

    Hi,

     

    For one of our customer we are searching after a MFA solution.

    We would like to build it with CPPM.

    Does CPPM have the possibility to send authenticating VPN users a SMS with an access token? We also want to have an e-mail option as failback in case the user doesn't respond to SMS.

     

    Kind regards,



  • 2.  RE: CPPM MFA

    EMPLOYEE
    Posted Oct 18, 2019 08:50 AM

    Which MFA provider do you have? SMS is not an option.



  • 3.  RE: CPPM MFA

    Posted Oct 18, 2019 09:01 AM

    We use SMSpasscode at the moment.

    So above solution doesn't work on CPPM?

     

    Kind regards,



  • 4.  RE: CPPM MFA

    EMPLOYEE
    Posted Oct 18, 2019 10:12 AM

    SMS is not considered a secure second factor so we do not support it for non-visitor flows.



  • 5.  RE: CPPM MFA

    Posted Oct 18, 2019 10:13 AM

    Ok, to get everything straight, the e-mail option is supported?

     

    Kind regards,



  • 6.  RE: CPPM MFA

    EMPLOYEE
    Posted Oct 18, 2019 10:24 AM

    No



  • 7.  RE: CPPM MFA

    Posted Oct 18, 2019 10:25 AM

    Ok, so the whole setup isn't supported on CPPM?

    Any proposals?



  • 8.  RE: CPPM MFA
    Best Answer

    EMPLOYEE
    Posted Oct 18, 2019 10:44 AM

    We cannot make recommendations for other products. Identity solutions should be selected based on security requirements.

     

    For CPPM UI, any MFA solution that's part of an existing login flow via SAML is supported. For TACACS+, any MFA solution that has a RADIUS agent component is supported.



  • 9.  RE: CPPM MFA

    Posted Apr 15, 2020 06:08 PM

    I think the customer should have the option to decide, SMS is considered very secure in many countries.