Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Customer wants to use ClearPass and Azure MFA (Multi Factor Authentication) for Cisco anyconnect VPN

This thread has been viewed 32 times
  • 1.  Customer wants to use ClearPass and Azure MFA (Multi Factor Authentication) for Cisco anyconnect VPN

    Posted Jul 04, 2019 03:06 AM

    Customer wants to use ClearPass and Azure MFA (Multi Factor Authentication) for Cisco anyconnect VPN users. Can this be done with ClearPass? attached doco explians how it's done with Cisco ASA and Azure.



  • 2.  RE: Customer wants to use ClearPass and Azure MFA (Multi Factor Authentication) for Cisco anyconnect VPN

    EMPLOYEE
    Posted Jul 05, 2019 11:39 AM

    It’s likely possible, but it’s not something that has been tested so it’s not supported by TAC. I should also add that Microsoft's Azure MFA Server has been deprecated and is not available for new install.



  • 3.  RE: Customer wants to use ClearPass and Azure MFA (Multi Factor Authentication) for Cisco anyconnect VPN

    Posted Aug 21, 2020 01:54 PM

    Good Afternoon!

    Has there been any change in 6.9 to support CPPM and Azure MFA via RADIUS?

    We are in the same boat, VPN solution that allows RADIUS, but can't directly talk to the Azure APIs for MFA.

     

    Thank you!



  • 4.  RE: Customer wants to use ClearPass and Azure MFA (Multi Factor Authentication) for Cisco anyconnect VPN

    Posted Aug 22, 2020 12:44 PM

    There is no native Azure MFA integration still with CPPM 6.9, you need to use NPS as a gateway/proxy to authN between CPPM <> NPS <> Azure MFA.



  • 5.  RE: Customer wants to use ClearPass and Azure MFA (Multi Factor Authentication) for Cisco anyconnect VPN

    Posted Oct 16, 2020 01:15 PM

    Could you explain further how to configure this? Any chance there is a white paper or similar on this configuration? We want to use Clearpass as our primary RADIUS, but have some requirements to use Azure MFA and SAML features. From what I've seen, you are correct and we would need to include NPS for the integration with Azure.

     

    Can you recommend any guides or resources for this? This is for a Pulse VPN solution that ideally uses computer certificate authentication, Azure MFA, and SAML SSO capabilities.