Security

last person joined: 22 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Need to setup an external RADIUS server as an Authentication source in CPPM

This thread has been viewed 5 times
  • 1.  Need to setup an external RADIUS server as an Authentication source in CPPM

    Posted Apr 29, 2015 02:53 PM

    Does ClearPass support an external RADIUS server as an authentication srouce?  I checked under authentication sources by adding a new authenticaiton source.  But I don't see an option under "Type" for "RADIUS Server".  The only option that would possibly apply in my case seems to be the "Token Server".  

     

    The reason why I need this is that I have a use case where we may need to point to an external SteelBelt radius. I will try to convince the client to just replace that system with ClearPass but in the mean time... 

     

    I wonder if anyone has tried to setup an external RADIUS server as an authentication source in CPPM?  And is Token Server the right option? 



  • 2.  RE: Need to setup an external RADIUS server as an Authentication source in CPPM

    EMPLOYEE
    Posted Apr 29, 2015 02:56 PM
    Are you on 6.5?


    Thanks,
    Tim


  • 3.  RE: Need to setup an external RADIUS server as an Authentication source in CPPM

    Posted Apr 29, 2015 03:04 PM

    Nah running 6.4.4 right now.  But since I am in the eval stages of the product I am open to anything that works. 



  • 4.  RE: Need to setup an external RADIUS server as an Authentication source in CPPM

    EMPLOYEE
    Posted Apr 29, 2015 03:28 PM
    6.5 adds support for external RADIUS authentication.

    Thanks,
    Tim


  • 5.  RE: Need to setup an external RADIUS server as an Authentication source in CPPM
    Best Answer

    Posted May 07, 2015 10:29 AM

    It looks like "Token Server" template may work to setup an external radius server.  It looks like clearpass acts as  a RADIUS proxy in this case.   I set it up and did some tests with a bogus account and with clearpass packet capture i see the radius request go out with "AVP - proxy state" defined.. I also see the external radius sever sends "access-rejects" in response to the proxy requests.  its rejected because I used a bogus account.  

     

    But seems like this would work... It makes sense since AmigoPod claimed that it could talk to external RADIUS servers a while back.  I guess it doesn't matter anymore since 6.5 has explicit support for external radius.  My guess is that its similar setup to the token server on 6.4.

     

    Thanks for pointing out the 6.5 support bit. I'll play with that when I upgrade. 



  • 6.  RE: Need to setup an external RADIUS server as an Authentication source in CPPM

    Posted Jul 25, 2019 06:49 AM

    Can you please let me know how to configure external Radius server for cppm login authentication and how to configure snmp string for polling the data, status of CPPM Server. I am using 6.7.9 version. 

     

     

    Regards

    Gaurav Pandey

     



  • 7.  RE: Need to setup an external RADIUS server as an Authentication source in CPPM

    EMPLOYEE
    Posted Jul 25, 2019 06:53 AM

    Please open your own thread.  This thread is years old.