Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass - Using EAP-PEAP for selected AD users

This thread has been viewed 15 times
  • 1.  Clearpass - Using EAP-PEAP for selected AD users

    Posted Nov 11, 2015 08:58 AM

    Hello,

     

    Our network uses mainly EAP-TLS for network auth and that is working fine, I'm trying to setup access for selected users via EAP-PEAP and I cannot seem to be able to have the request hit the right rule.

     

    We use Clearpass and I have setup two 802.1x rules one for users trying to authenticate with EAP-PEAP on top of the main one for EAP-TLS auth.

     

    2015-11-11 08_36_23-ClearPass Policy Manager - Aruba Networks.png

     

    My problem is, even with the Authentication OuterMethod set to EAP-PEAP, users never seem to hit that rule.

     

    2015-11-11 08_47_10-Photos.png

     

    This particular user should have hit the PEAP rule but did not.

     

    Any ideas on how I could make sure that EAP-PEAP users will hit the first rule?

     

    Thanks



  • 2.  RE: Clearpass - Using EAP-PEAP for selected AD users

    EMPLOYEE
    Posted Nov 11, 2015 09:08 AM
    Add mschap as an authentication method.


  • 3.  RE: Clearpass - Using EAP-PEAP for selected AD users

    Posted Nov 11, 2015 09:56 AM

    Hi cjoseph,

     

    I've tried MSCHAP and EAP-MSCHAPv2 as both inner and outer methods with no luck.

     

    Thanks



  • 4.  RE: Clearpass - Using EAP-PEAP for selected AD users

    Posted Nov 11, 2015 10:03 AM

    I should add that I did put MSCHAP as an Authentication method :

     

    2015-11-11 10_03_29-Photos.png

     

    Thanks



  • 5.  RE: Clearpass - Using EAP-PEAP for selected AD users

    Posted Nov 11, 2015 11:40 AM

    Would it be possible to add a Service condition that if a user matches an AD Group?

     

    On a Microsoft NPS server this was possible, I'm trying to replicate this on Clearpass.



  • 6.  RE: Clearpass - Using EAP-PEAP for selected AD users

    EMPLOYEE
    Posted Nov 11, 2015 03:44 PM

    Don't know if you got it fixed, but this is how mine is working:

    peap.png



  • 7.  RE: Clearpass - Using EAP-PEAP for selected AD users

    Posted Nov 11, 2015 03:49 PM

    No I haven't got it working correctly, but I will try adding both MSCHAP and EAP MSCHAPv2 and report back.

     

    Thanks



  • 8.  RE: Clearpass - Using EAP-PEAP for selected AD users

    Posted Nov 11, 2015 03:58 PM

    It's not working for me. Can I ask what are your service conditions?



  • 9.  RE: Clearpass - Using EAP-PEAP for selected AD users

    EMPLOYEE
    Posted Nov 11, 2015 04:05 PM

    It is pretty bare (PAP only is needed for Captive Portal-you can ignore that).

    8021x-service-bare.png



  • 10.  RE: Clearpass - Using EAP-PEAP for selected AD users
    Best Answer

    Posted Nov 11, 2015 04:38 PM

    Seems to me that Colin is answering for a pure EAP-PEAP case, not the question Yann is trying to get answered.

     

    Yann, seems you can't use Authentication type during service categorization. It's probably logical (too early in the process or whatever), but someone with more knowledge of the process will have to explain why ;)

     

    One way you could solve it is to add EAP-PEAP to main .1x serviceIn the role mapping do a test for "Authentication OuterMethod equals EAP-PEAP" AND the AD group you mentioned and give it a custom role like "EAP-PEAP-USER". Now you're free to add a "Tips Role NOT EQUALS EAP-PEAP-USER" to the EAP-TLS tests and whatever needed in the enforcement policy to give the EAP-PEAP-USER access..

     



  • 11.  RE: Clearpass - Using EAP-PEAP for selected AD users

    Posted Nov 12, 2015 08:49 AM

    John, you hit the proverbial nail on the head. Your explanation caused several puzzle pieces to fall in place.

     

    I went back to a bare bones service condition and let the enforcement policy do the heavy lifting. It is now working like a champ.

     

    Thank you all for your input!



  • 12.  RE: Clearpass - Using EAP-PEAP for selected AD users

    Posted Apr 28, 2021 12:45 PM
    @Yann

    I land in the same situation as yours, will you be able to share me snapshot of your configuration, please.​

    ------------------------------
    Faizan Sayed
    ------------------------------



  • 13.  RE: Clearpass - Using EAP-PEAP for selected AD users

    Posted Nov 11, 2015 06:50 PM
    You may need to look at access tracker > Input > Radius request and make sure that you have all the necessary attributes to match in the service.

    Another thing you could try and do is use the Authentication:OuterMethod Not Equal EAP-TLS and see if it works.