Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

New Clearpass Guest w/ onboard system, need some guidance on provisioning!

This thread has been viewed 0 times
  • 1.  New Clearpass Guest w/ onboard system, need some guidance on provisioning!

    Posted Aug 14, 2012 01:21 PM

    Hi, 

     

    Turns out these forums are invaluable when setting up Wifi! Anyways, my issue is that I cannot get device provisioning to work correctly. My goal is to have non provisioned devices connect to "Mobile Provisioning" SSID then authenticate user via AD credentials and install certificate for Provisioned network.

     

    Everything works perfectly up to the last step where the device switches connections and tries to authenticate using the newly installed certs. For some reason the profile that gets installed on the device appends the username with ":(certificate serial number):mdps_generic, ie john.doe:5:mdps_generic. If it did not append, then it would work! (I am pretty sure anyways).

     

    Question: Can I remove the strig that gets added on to the user name? Or am I setting this up all wrong?

     

    Using Aruba Controller

    CP Onboard is a sub. CA to our windows CA

    AD is set to authenticate users before provisioning (works)

    Once reconnect to provisioned SSID our NPS server states user does not exist -> reject. 

     

    Thanks in advance for any advice on this and let me know if any other info is needed!!

     

     

     

     

     



  • 2.  RE: New Clearpass Guest w/ onboard system, need some guidance on provisioning!

    Posted Aug 14, 2012 02:24 PM

    Glad you are finding the forums here useful. A couple of things to consider with your Onboard deployment that might be useful. Onboard currently supports two classes of device credentials that will be installed on the provisioned devices during the Onboard process.

     

    The ClearPass Policy Manager is designed to support both classes of these device credentials and you are potentially hitting an issue where the MS NPS is not aware of the method to authenticate the credential you are highlighting.

     

    Please speak to your local Aruba account team or partner and they should be able to advise you on the best path to implement Onboard on your environment.



  • 3.  RE: New Clearpass Guest w/ onboard system, need some guidance on provisioning!

    Posted Aug 14, 2012 03:10 PM

    Hi -cam-

     

    Thanks for the fast response. That make sense the the NPS does not understand what Clearpass provisioned user profile is saying. 

     

    One point which I did not mention is that even though all the equipment is aruba, we got it from Dell so everything is dell branded. I do have a case open with them, but I just wanted to understand the process(es) for onboarding so I would also have a good idea which way to go. (in a timley fastion...)

     

    One thing I have seen mentioned in regrads to onboarding scenarios is having a proxy radius server, but that seems to only make sense when Onboard is the CA

     

    Thanks!



  • 4.  RE: New Clearpass Guest w/ onboard system, need some guidance on provisioning!

    Posted Aug 16, 2012 09:43 AM

    Hi, 

     

    After going through all of the airhead's discussions on provisioning again, I believe I know what the solution is. Looks like we need to set up our NPS server to have a remote Radius server (proxy clearpass server) and set it so that when certain radius requests are made to the NPS server to sends them to clearpass to approve or reject.

     

    I have not tested this yet, so ill update when I do.

     

    Thanks,  



  • 5.  RE: New Clearpass Guest w/ onboard system, need some guidance on provisioning!



  • 6.  RE: New Clearpass Guest w/ onboard system, need some guidance on provisioning!

    Posted Aug 16, 2012 10:58 AM

    Thanks for the link, I did come accross it before. Only thing is that we are not using Clearpass Policy Manager. :(

     

     



  • 7.  RE: New Clearpass Guest w/ onboard system, need some guidance on provisioning!

    Posted Aug 24, 2012 11:35 AM

    Just an update:

     

    The suffix that is getting added to the username only happens when it is a provisioned android not an iPad.....

     

    Thanks,



  • 8.  RE: New Clearpass Guest w/ onboard system, need some guidance on provisioning!

    EMPLOYEE
    Posted Aug 24, 2012 07:59 PM

    That is because the Android device uses PEAP, which is username and password, and the iPAD uses a TLS certificate.