Security

last person joined: 18 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Can Webauth use an external Radius to authenticate?

This thread has been viewed 2 times
  • 1.  Can Webauth use an external Radius to authenticate?

    Posted Apr 15, 2014 03:50 AM

    Hi,

     

    Is there any way to add an external Radius Server as Authentication Source?

     

    My customer wants to use the web page on CPPM, then the username/password will be authenticated by their existing external Radius Server.

     

    Thanks in advance.

     

     

     

    Regards,

    Patrick

     



  • 2.  RE: Can Webauth use an external Radius to authenticate?

    Posted Apr 15, 2014 05:41 AM

    You could probably achieve this by setting up a RADIUS proxy target and service.

     

    Configuration>Network>Proxy Targets

    Configuration>Services>Add Service (type RADIUS Proxy)



  • 3.  RE: Can Webauth use an external Radius to authenticate?

    Posted Apr 15, 2014 05:43 AM

    Thanks.

     

    But in order for Radius Proxy to work, you have to receive a Radius request in the first place....

     

    In my situation, the authentication request is from the ClearPass Web page (WebAuth). So this will never hit the Radius Proxy service. Any other idea?

     

    Thank you very much.

     

    Patrick

     



  • 4.  RE: Can Webauth use an external Radius to authenticate?

    Posted Apr 16, 2014 02:18 PM

    I see. There might be options...

     

    Can you expand more on what your customer is really trying to achieve?

     

    I.e. so this user is looking at a webpage (username/password) on Clearpass. For what purpose? How did they get there? And then what happens if they enter valid details?

     



  • 5.  RE: Can Webauth use an external Radius to authenticate?

    Posted Apr 16, 2014 10:34 PM

    Thanks. The scenario is:

     

    LanSwitch---------CPPM---------------3rd_Party_radius

     

     

    The LanSwitch can redirect client to CPPM guest page for authentication, but customer doesn’t want to use CPPM as authentication source. They have centralized Radius.

     

    So if CPPM  can send the username/passwd to 3rd party radius for authentication, when succeeded, CPPM sends a COA to LanSwitch to change client role.

     

    If you need more info please let me know.

     

    I heard that we can make CPPM to change Guest request from WebAuth to Radius_Auth. But I don't know how.

     

    Regards,

    Patrick

     

     

     



  • 6.  RE: Can Webauth use an external Radius to authenticate?

    Posted Apr 17, 2014 03:11 AM

    Under a normal deployment type (for instance with an Aruba controller or IAP), it's the network device that converts the web login to a RADIUS which it then sends to Clearpass (which you could then proxy).

     

    If a user is looking directly at a Clearpass page, the Clearpass would have to understand something about how the user got there and what to do next.

     

    I.e. when a user types in details, think about how you expect the Clearpass to know how we got to this point and where the "LANSwitch" is with which we need to communicate. AND, when the details are entered (assuming Clearpass knows the switch involved), what should it send back to that switch to tell it the user is "ok" and can now be treated differently.

     

    So, when you say "LANSwitch", what manufacturer and product model is the user connected to (you'd have to understand this to model it)? And how specifically does this device redirect the user in your scenario? Futhermore, if you're talking COA, this would assume the network device is involved in a RADIUS conversation with Clearpass in the first place. So how is it doing that (protocol, feature, maybe like Cisco WCCP)?



  • 7.  RE: Can Webauth use an external Radius to authenticate?

    Posted Apr 18, 2016 03:13 PM

    Was this ever solved? I'm trying to use RADIUS as authentication source from CPPM.



  • 8.  RE: Can Webauth use an external Radius to authenticate?

    Posted Apr 19, 2016 01:00 AM

    Yes it had been solved.

     

    However maybe your requirement is different if you wanted to use CMMP as Radius Server.

     



  • 9.  RE: Can Webauth use an external Radius to authenticate?

    Posted Jul 20, 2016 02:45 PM

    @pydiao wrote:

    Yes it had been solved.

     


    can you explain how for the case of the third party radius server?