Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Eduroam - Enable Radius Accounting Only for On-Campus Users

This thread has been viewed 4 times
  • 1.  Eduroam - Enable Radius Accounting Only for On-Campus Users

    Posted Apr 01, 2020 06:44 PM

    We're currently looking into the idea of making "eduroam" our primary 802.1X network in addition to adding of EAP-TLS as an authentication method. When we first went live with eduroam, our clearpass administrator was informed that it was advised that we disable "Radius Accounting" on our controllers as to prevent accounting messages from being forwarded. I wanted to inquire if it was possible to keep the "Radius Accounting" messages enabled for Clearpass on local/home/visiting users on campus- but DO NOT forward them to the eduroam radius proxies?



  • 2.  RE: Eduroam - Enable Radius Accounting Only for On-Campus Users

    Posted Apr 01, 2020 08:12 PM
    On your firewall only allow outbound 1812 and 1645 to the eduroam proxy servers

    accounting uses 1813 and 1646