Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass 802.1x service for Aruba Cluster

This thread has been viewed 0 times
  • 1.  ClearPass 802.1x service for Aruba Cluster

    Posted Nov 29, 2018 07:08 AM

    Hi,

     

    I have four Aruba 7220 controllers in cluster with VRRP on each controller plus VRRP IP for "aruba-master" for new APs. Everything managed from Mobility Master.

     

    Client AD authentication - Do I need to setup four 802.1x Services on ClearPass server to get 802.1x work or can I use only one service there I have all four controllers together, in same service?

     

    What is a best-practice?



  • 2.  RE: ClearPass 802.1x service for Aruba Cluster

    Posted Nov 29, 2018 07:22 AM
    In most cases one service for wireless 802.1X should be fine



    Thank you

    Victor Fabian

    Pardon typos sent from Mobile


  • 3.  RE: ClearPass 802.1x service for Aruba Cluster

    Posted Nov 29, 2018 07:47 AM
      |   view attached

    Thanks for your fast reply!

     

    Well, that's what I tried to do but...

     

    I have APs and clients on all four Aruba controllers which means that authentications request coming from all four controllers. And as 802.1x service is build I can't have a NAD-gruop only one MD per service, or? 

    See attached file.

     

    How you guys do with authentications coming from Aruba Cluster and from different controllers?



  • 4.  RE: ClearPass 802.1x service for Aruba Cluster

    Posted Nov 29, 2018 09:38 AM
    You can create a device attribute under configuration > network devices > attribute tab > device (device type or device id) and then you can include that in the service

    Sent from Mail for Windows 10


  • 5.  RE: ClearPass 802.1x service for Aruba Cluster
    Best Answer

    Posted Dec 04, 2018 07:19 AM
      |   view attached

    I would choose one of the following options:

     

    1. Configure a device group under Configuration >> Network >> Device Group and match the device group in the service 
    2. Use a regular expression in the service

    Check the screenshot for an example

     

     



  • 6.  RE: ClearPass 802.1x service for Aruba Cluster

    EMPLOYEE
    Posted Nov 29, 2018 09:25 AM
    Just put all the controller IPs in one NAD group. Also keep in mind that using NAS groups is optional.