Security

last person joined: 9 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Extension BlackBerry Unified Endpoint Manager

This thread has been viewed 1 times
  • 1.  ClearPass Extension BlackBerry Unified Endpoint Manager

    Posted Mar 05, 2019 01:20 PM
      |   view attached

    Hi 

     

    I have followed the attached document to use our BlackBerru UEM server as an Authentication Source. I would now like to create a service but I do not know which type of service i should choose. Would anyone have some guidance on the Service Creation.

     

    Thanks



  • 2.  RE: ClearPass Extension BlackBerry Unified Endpoint Manager

    EMPLOYEE
    Posted Mar 05, 2019 01:23 PM
    What are you trying to authenticate?


  • 3.  RE: ClearPass Extension BlackBerry Unified Endpoint Manager

    Posted Mar 05, 2019 04:38 PM

    I am trying to authenticate Employee Cell Phones that are registerd with Blackberry UEM which is an MDM solution. When they join the specific wireless network Clearpass will authenticate the device against our BES UEM server.



  • 4.  RE: ClearPass Extension BlackBerry Unified Endpoint Manager

    EMPLOYEE
    Posted Mar 05, 2019 04:40 PM
    Use an 802.1X wireless service template.


  • 5.  RE: ClearPass Extension BlackBerry Unified Endpoint Manager

    Posted Mar 05, 2019 04:56 PM

    I did try your suggested Service but i received the following error

     

    ""HTTP type Authentication Source is not supported for RADIUS services""     



  • 6.  RE: ClearPass Extension BlackBerry Unified Endpoint Manager

    EMPLOYEE
    Posted Mar 05, 2019 04:59 PM
    The extension should be used as an Authorization source.


  • 7.  RE: ClearPass Extension BlackBerry Unified Endpoint Manager

    Posted Mar 06, 2020 03:07 PM

    Run into the exact same issue.

     

    Initially, have been trying to use a perfectly working EAP-TLS service for corporate machines and add the BlackBerry UEM authorization source to allow corporate-managed phones (valid certificate and UEM-managed is the role mapping).

     

    Fail the authentication, obviously cause it only has the AD and UEM cannot be added there.

     

    Tried duplicating the service and have 2 separate, but 802.1X template does not allow me to remove authentication source and methods, and only use authorization.

     

    Is there something I'm missing?