Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass as RADIUS Client

This thread has been viewed 1 times
  • 1.  Clearpass as RADIUS Client

    Posted Jul 28, 2018 06:08 AM

    For 802.1X based authentication, WLC acts as an authenticator and in turn communicates with external RADIUS servers. But NAS (Network Access Server) may be sperate from WLC e.g clearpass can be NAS.

    So in the following network architecture, where Clearpass is acting as a NAS (and doing access control based on Radius respone from AAA), what shall be the communication mechanism between WLC and NAS (Note: it's 802.1x authentication)?

     

    UE <--(EAPOL)--> WLC <--(??)--> NAS <---(RADIUS)----> AAA Server

     



  • 2.  RE: Clearpass as RADIUS Client

    EMPLOYEE
    Posted Jul 28, 2018 08:29 AM
    RADIUS or RadSec is used between the NAS and the RADIUS server.


  • 3.  RE: Clearpass as RADIUS Client

    Posted Jul 28, 2018 08:48 AM
    That is correct but my question was what protocol is used between WLC and NAS for 802.1x? If authenticator runs on WLC then how does NAS sniff RADIUS replies from RADIUS Server for user access control?


  • 4.  RE: Clearpass as RADIUS Client

    EMPLOYEE
    Posted Jul 28, 2018 08:51 AM
    The WLC is the NAS. Not sure I understand your question. NAS to AAA server uses the RADIUS or RadSec protocols.


  • 5.  RE: Clearpass as RADIUS Client

    Posted Jul 28, 2018 08:56 AM
    Let me ask it this way.

    1) Can we can a NAS which is separate from WLC for 802.1x auth?

    In following way:
    UE <—> WLC <—> NAS <—> RADIUS-Server

    2) Clearpass itself can act as NAS for 802.1x? Right?


  • 6.  RE: Clearpass as RADIUS Client

    EMPLOYEE
    Posted Jul 28, 2018 08:58 AM
    The NAS is always the WLC.

    What are you actually trying to do/accomplish? Take out the terminology for a second.


  • 7.  RE: Clearpass as RADIUS Client

    Posted Jul 28, 2018 09:11 AM
    Okay. Our AAA server is external and WLC is configured for 802.1x (EAP-TTLS). We are using Palo Alto as Firewall along with access control.

    Once the AAA server has authenticated the user, it categories the users in certain access categories (in Access-Accept). But these categories have to be applied to Palo Alto which is being controlled by an entity (say X, which is kind of access controller).

    Now because Access-Accept reaches WLC and not X, how to configure the firewall from X based on RADIUS server response?


    [e.g imagine X is clearpass].