Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Sponsor Lookup SAML/ADFS

This thread has been viewed 0 times
  • 1.  Clearpass Sponsor Lookup SAML/ADFS

    Posted Jun 28, 2016 04:06 PM

    Does anyone know if you can do sponsor lookups via ADFS or SAML?

     

     



  • 2.  RE: Clearpass Sponsor Lookup SAML/ADFS

    EMPLOYEE
    Posted Jun 28, 2016 04:58 PM
    SAML is an authentication method. You can do lookups against an LDAP server only.


  • 3.  RE: Clearpass Sponsor Lookup SAML/ADFS

    Posted Jun 28, 2016 05:11 PM
    Server guy suggestion I've never implemented it.

    So what's the preferred method of doing sponsor lookups against several domain controllers?
    Please visit us at http://www.teletech.com
    ............................................................
    This EMAIL and any attachments may contain confidential, proprietary and/or privileged information. If you are not the intended recipient, please immediately notify the sender by return email, and delete this communication and any copies. Any dissemination or use of this information by a person other than the intended recipient is unauthorized and may be subject to criminal and civil proceedings. Unless otherwise stated, opinions expressed in this email are those of the author and are not endorsed by TeleTech Holdings.
    ............................................................


  • 4.  RE: Clearpass Sponsor Lookup SAML/ADFS

    EMPLOYEE
    Posted Jun 28, 2016 09:41 PM

    Are they different domains?



  • 5.  RE: Clearpass Sponsor Lookup SAML/ADFS

    Posted Jun 28, 2016 11:34 PM
    They're all under our domain.com structure but basically we have a pair per geographical region with the primary in one datacenter and the secondary in the geographical region.

    So we may have

    Domain.com
    Country.domain.com
    Country2.domain.com

    Basically 5 different DC pairs. Writing CPPM rules are a blast because of this.


    Please visit us at http://www.teletech.com
    ............................................................
    This EMAIL and any attachments may contain confidential, proprietary and/or privileged information. If you are not the intended recipient, please immediately notify the sender by return email, and delete this communication and any copies. Any dissemination or use of this information by a person other than the intended recipient is unauthorized and may be subject to criminal and civil proceedings. Unless otherwise stated, opinions expressed in this email are those of the author and are not endorsed by TeleTech Holdings.
    ............................................................


  • 6.  RE: Clearpass Sponsor Lookup SAML/ADFS

    EMPLOYEE
    Posted Jun 29, 2016 06:40 AM

    Do you already have sponsorship lookups working via LDAP?   You should do that first to get the feel of it before deciding if you possibly want to do that with multiple domains.



  • 7.  RE: Clearpass Sponsor Lookup SAML/ADFS

    Posted Jun 29, 2016 01:28 PM
    I do. can it look across 5 servers?
    Please visit us at http://www.teletech.com
    ............................................................
    This EMAIL and any attachments may contain confidential, proprietary and/or privileged information. If you are not the intended recipient, please immediately notify the sender by return email, and delete this communication and any copies. Any dissemination or use of this information by a person other than the intended recipient is unauthorized and may be subject to criminal and civil proceedings. Unless otherwise stated, opinions expressed in this email are those of the author and are not endorsed by TeleTech Holdings.
    ............................................................


  • 8.  RE: Clearpass Sponsor Lookup SAML/ADFS

    EMPLOYEE
    Posted Jun 29, 2016 01:37 PM

    Unfortunately only a single server is supported at a time..



  • 9.  RE: Clearpass Sponsor Lookup SAML/ADFS

    Posted Jun 29, 2016 03:00 PM
    So the only solution is probably going to be OpenLdap acting as a proxy to farm the query across all servers.

    Please visit us at http://www.teletech.com
    ............................................................
    This EMAIL and any attachments may contain confidential, proprietary and/or privileged information. If you are not the intended recipient, please immediately notify the sender by return email, and delete this communication and any copies. Any dissemination or use of this information by a person other than the intended recipient is unauthorized and may be subject to criminal and civil proceedings. Unless otherwise stated, opinions expressed in this email are those of the author and are not endorsed by TeleTech Holdings.
    ............................................................


  • 10.  RE: Clearpass Sponsor Lookup SAML/ADFS

    EMPLOYEE
    Posted Jun 29, 2016 03:17 PM

    I guess the big question is, do you want to have guests pull up every "Robert" at the company to request a guest account?



  • 11.  RE: Clearpass Sponsor Lookup SAML/ADFS

    Posted Jun 29, 2016 04:01 PM
    We'll it will be several years until they are all collapsed into a single AD pair, so I do not really have a choice.

    Please visit us at http://www.teletech.com
    ............................................................
    This EMAIL and any attachments may contain confidential, proprietary and/or privileged information. If you are not the intended recipient, please immediately notify the sender by return email, and delete this communication and any copies. Any dissemination or use of this information by a person other than the intended recipient is unauthorized and may be subject to criminal and civil proceedings. Unless otherwise stated, opinions expressed in this email are those of the author and are not endorsed by TeleTech Holdings.
    ............................................................


  • 12.  RE: Clearpass Sponsor Lookup SAML/ADFS

    EMPLOYEE
    Posted Jun 29, 2016 04:07 PM

    What is the organization doing now for sponsorship?  Can't they have a hybrid approach that could involve the receptionist or a kiosk?  I does not have to be 100% sponsorship, right?