Security

last person joined: 15 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM - Tacacs auth with AD credenciais plus Mfa (duo)

This thread has been viewed 8 times
  • 1.  CPPM - Tacacs auth with AD credenciais plus Mfa (duo)

    Posted Feb 23, 2017 07:26 AM
    Can cppm do this type of auth?
    Example: user John will log to a router with his user name and a password wich is made of his AD password and mfa token with a coma in between (adpwd,mfatoken).
    Cppm will send adpwd via Ldap to AD and mfatoken to duo security cloud.


  • 2.  RE: CPPM - Tacacs auth with AD credenciais plus Mfa (duo)

    Posted Feb 23, 2017 11:18 AM
    No, well, I think it might be possible but not without a little help from a couple of Duo applications.

    This guide will get you going: https://duo.com/docs/syncing_users_from_active_directory

    You wouldn't need to add the mfatoken to the username.

    The (very basic) flow would be:

    User authenticates on switch/router
    TACACS or RADIUS request is sent CPPM
    CPPM sends request to Duo Authentication Proxy
    Duo Authentication Proxy sends request to Duo
    Duo sends MFA request to users MFA device (smartphone I assume)
    User accepts MFA request & gains access to switch/router



  • 3.  RE: CPPM - Tacacs auth with AD credenciais plus Mfa (duo)

    Posted Feb 23, 2017 12:10 PM
    Thanx for the reply James, yeah i know that using DUO proxy i can do it, even with the token as the proxy will strip it and send one part to the AD and another to the cloud. What i wanted to kwow is if the CPPM could do the work of the proxy so we wouldn´t need another machine in the solution (the DUO proxy). PS - i have seen some docs for using DUO directly from CPPM but only for Guest access...


  • 4.  RE: CPPM - Tacacs auth with AD credenciais plus Mfa (duo)
    Best Answer

    EMPLOYEE
    Posted Feb 23, 2017 12:13 PM
    Yes, the native Duo hooks are for web based workflows.


  • 5.  RE: CPPM - Tacacs auth with AD credenciais plus Mfa (duo)

    EMPLOYEE
    Posted Feb 23, 2017 12:13 PM
    Yes, the native Duo hooks are for web based workflows.