Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

OnGuard VPN (EAP-TLS Machine Cert Auth) with Health Checks (no Auth)

This thread has been viewed 0 times
  • 1.  OnGuard VPN (EAP-TLS Machine Cert Auth) with Health Checks (no Auth)

    Posted Nov 18, 2016 11:16 AM

    Hi All,

     

    Can someone briefly explain to me how this works?

     

    OnGuard VPN (EAP-TLS Machine Cert Auth) with Health Checks (no Auth)

     

    On the ClearPass access tracker VPN authentications always have a posture as unknown, even when the client shows health status as healthy and directly after a successful health check.

     

    Is this happening due to Via clients MAC address showing as 00:00:00:00:00:00 (as per the outstanding bug)??

     

    Cheers

    James

     

     



  • 2.  RE: OnGuard VPN (EAP-TLS Machine Cert Auth) with Health Checks (no Auth)

    Posted Dec 06, 2016 07:30 AM

    Bump.

     

    I'm not sure what would link the authenticated client to the health check other than the MAC address but as it all zeros... How would this work?



  • 3.  RE: OnGuard VPN (EAP-TLS Machine Cert Auth) with Health Checks (no Auth)

    EMPLOYEE
    Posted Dec 08, 2016 10:16 AM

    Sorry for the delay. When using OnGuard with VPN, you need to do Health Checks with Authentication.



  • 4.  RE: OnGuard VPN (EAP-TLS Machine Cert Auth) with Health Checks (no Auth)

    Posted Dec 09, 2016 04:43 AM

    Hi Tim,

     

    Thanks for the reply. I'm authenticating using a TLS machine certificate (no authorization) and doing domain pre-connect. In this scenario if I enabled health check with auth would it work or would I also need to enable authorization on my EAP-TLS authenticaiton method?

     

    Reason for asking is, in my scenario, using health check with authentication would mean CPPM would see 2 authentication requests. 1 would be from the machine for VPN auth and the other from the user for health check auth. Would CPPM know the health check authentication was from the same device as the machine based TLS auth?

     

    Cheers

    James



  • 5.  RE: OnGuard VPN (EAP-TLS Machine Cert Auth) with Health Checks (no Auth)

    Posted Dec 13, 2016 07:10 AM

    Just to add a bit more details.

    Here's a successful healthy posture.

    via healthy.jpg

     

    Immediately (9 seconds later) followed by my Via authentication:

    via unknown.jpg

    So my posture was healthy, then it was unknown.

     

    I have cached roles and posture enabled.

    via cached.jpg

     

     



  • 6.  RE: OnGuard VPN (EAP-TLS Machine Cert Auth) with Health Checks (no Auth)

    Posted Jan 03, 2017 08:47 AM

    FYI this configuration is not supported.

     

    The username in the certificate needs to match the username in the health check so only user certificate will work with health checks with authentication.

     

    Currently machine based certificate don't work with health checking.



  • 7.  RE: OnGuard VPN (EAP-TLS Machine Cert Auth) with Health Checks (no Auth)

    Posted Mar 03, 2017 07:35 AM
    UPDATE: Aruba Engineering are working on a fix for this.