Security

last person joined: 14 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass and AD user authentication process explanation

This thread has been viewed 3 times
  • 1.  ClearPass and AD user authentication process explanation

    Posted Oct 18, 2016 05:57 AM

    Hello Guys,

     

    Could someone explain to me how IAP VC authenticate users to the AD database with ClearPass server? My understanding is that particular SSID is configured to use authenticate the server. That RADIUS server is a ClearPass server. Is clear pass talking to the AD server then user is trying to access the network or actually IAP VC? On the AD server to i need to allow as a RADIUS client only ClearPass server or all IAP VC?

     

    Cheers,

    Myky



  • 2.  RE: ClearPass and AD user authentication process explanation
    Best Answer

    EMPLOYEE
    Posted Oct 18, 2016 06:09 AM
    ClearPass talks to your domain controllers. Your IAPs talk to ClearPass.


  • 3.  RE: ClearPass and AD user authentication process explanation

    Posted Oct 18, 2016 06:16 AM

    ok good and thanks. So ClearPass is asking to authenticate a particular user and providing credentials (username/password) to the ADs where IAP VCs are only sending it to the ClearPass?



  • 4.  RE: ClearPass and AD user authentication process explanation
    Best Answer

    Posted Oct 18, 2016 06:42 AM
    You only need ClearPass to talk to AD
    https://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/What-are-the-ports-that-need-to-be-opened-on-the-network/ta-p/175872

    On IAP side you need to assign an IP address to the VC per cluster and enable dynamic radius proxy and that should be use as your RADIUS client that needs to talk to ClearPass

    Get Outlook for iOS


  • 5.  RE: ClearPass and AD user authentication process explanation

    Posted Oct 18, 2016 06:58 AM

    Thanks all Guys