Security

last person joined: 14 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all
This thread has been viewed 40 times
  • 1.  Okta MFA

    Posted Jan 29, 2019 02:40 PM

    I have been asked if we can use Okta for multifactor authentication of our remote VPNs and other services. I see where Okta can be used for SSO and Onboard, but I would need it for a RADIUS Service. I saw a post from 2017 that says this may be depreciated, but as of 6.7.7 you can add Okta as an auth source type. However, I see no documentation on how to use it. 

     

    Can someone shed some light on Okta integration and if it can be used this way?



  • 2.  RE: Okta MFA

    EMPLOYEE
    Posted Jan 29, 2019 02:42 PM
    Can you please expand on the end to end workflow?


  • 3.  RE: Okta MFA

    Posted Jan 29, 2019 02:57 PM

    Currently, our VPN users are connecting using a combination of their username and code from google authenticator as there username and they use their password as the password. That request goes to clearpass and it forwards to a server that can parse the creds and sends back an accept or deny.

     

    Not sure if Okta can do a similar parse or do a push verify to their app when a user tries to connect. 



  • 4.  RE: Okta MFA
    Best Answer

    EMPLOYEE
    Posted Jan 29, 2019 02:59 PM
    You can deploy the same thing using the Okta RADIUS server configured as a Token Server auth source in ClearPass.


  • 5.  RE: Okta MFA

    Posted Jan 29, 2019 03:07 PM

    So it is correct that this will be going away?

    image.png



  • 6.  RE: Okta MFA

    EMPLOYEE
    Posted Jan 29, 2019 03:10 PM
    Yes, it will. It is not supported and was used for a previous integration that is no longer available.


  • 7.  RE: Okta MFA

    Posted Apr 29, 2019 06:55 PM

    Is there any how-to documentation for using 2FA/Token-based authentication for RADIUS supplicants?



  • 8.  RE: Okta MFA

    EMPLOYEE
    Posted Apr 29, 2019 07:49 PM
    Do you mean 802.1X workflows?


  • 9.  RE: Okta MFA

    Posted Apr 29, 2019 07:55 PM

    Yes for 802.1x, thanks

     



  • 10.  RE: Okta MFA

    EMPLOYEE
    Posted Apr 29, 2019 07:58 PM
    There is really no scalable way to do MFA at the supplicant level.


  • 11.  RE: Okta MFA

    Posted Apr 29, 2019 08:10 PM

    How about any general token server how-to docs, like e.g. for the OP's VPN workflow? Clearpass user docs show how to set up Token servers but doesn't give example use cases of what can be achieved with them.