Security

last person joined: 18 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass authentication source

This thread has been viewed 3 times
  • 1.  ClearPass authentication source

    Posted Oct 16, 2015 09:29 AM

    Dear Community,

     

    Is it any difference between the following two methods using ClearPass?Which one is recommended?

    1. Create an authentication source (e.g. Active Directory) with a Backup server, and use this authentication source when we create a service.
    2. Create two authentication sources with no backup servers, and use them in a service as authentication sources.

    Thank you for your answer in advance.

    Best regards,

     



  • 2.  RE: ClearPass authentication source

    EMPLOYEE
    Posted Oct 16, 2015 09:33 AM
    The backup server parameter only provides a backup ldap server to look the user up to see if that user exists. If you are using 802.1x the actual server utilized is determined by which one AD directs the authentication request to. What are you trying to accomplish?


  • 3.  RE: ClearPass authentication source

    Posted Oct 16, 2015 09:54 AM

    Dear Cjoseph,

     

    We are not trying to accomplish anything special, just want to know which one is best. 

    We just wondering if it is any difference between the two solutions.

    If we have two replicated ADs, than it is the best way to create an authentication source with a backup instead of create two authentication source. Am I right?

     

     



  • 4.  RE: ClearPass authentication source

    EMPLOYEE
    Posted Oct 16, 2015 09:56 AM
    Create a single AD source with the domain name as the server name. 


    Thanks, 
    Tim


  • 5.  RE: ClearPass authentication source
    Best Answer

    EMPLOYEE
    Posted Oct 16, 2015 10:00 AM
    If you are doing 892.1x with clearpass, there are two parts:

    1. Ldap lookup to find the user
    2. 802.1x authentication with AD.

    For #1 you need to create your own redundancy for the ldap lookup of the user. You should enter a backup IP address specifically for that or just put the fqdn of the domain for clearpass to choose a server randomly.
    For #2 the request is just sent off to any available domain controller so in a way there is built in redundancy.

    I hope this makes sense.


  • 6.  RE: ClearPass authentication source

    Posted Oct 16, 2015 10:04 AM

    Ok, thank you!