Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Wired authentication

This thread has been viewed 7 times
  • 1.  Clearpass Wired authentication

    Posted Dec 08, 2015 07:11 PM

    Hi All, 

     

    I am looking to perform wired user authetication via CLearpass and I am totally new to CP. Please help me out. 

     

    Here is my case that I want to implement ( It is really simple, but I am looking for some direction) : 

    1. If user connects to the wired network and has a valid certificate, then user must be assigned an employee VLAN

    2. If user connects to the wired network and does not have a valid cert, user is assigned a guest VLAN. 

     

    How can I implement this using CP ? There is no wireless involved. 



  • 2.  RE: Clearpass Wired authentication

    EMPLOYEE
    Posted Dec 08, 2015 07:13 PM
    What switch vendor and model?
    What's the client mix?
    Who is issuing the certificate?

    Sent from Nine


  • 3.  RE: Clearpass Wired authentication

    Posted Dec 08, 2015 07:18 PM

    Brocade ICX switches ,

    Clients are primarily latops ( wired auth only, no wireless users)

    Certificate is being issued by a trusted CA .. Radius is being used.



  • 4.  RE: Clearpass Wired authentication
    Best Answer

    Posted Dec 26, 2015 09:24 AM

    the CPPM side is quite easy, but on your switch side i can't say anything.

     

    you just build a general service for wired with EAP-TLS authentication and load the CA in the certificate list. next to the radius accept you will send the VLAN ID to the switch.

     

    the question is then what to do on the switch side. you will have to configure the switch to do dot1x authentication and configure the cppm as the radius server.

     

    the final step will be the guest vlan, you would have to do something with a fallback vlan when auth fails. this isn't something very common, but again it is something switch related.