Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Persistent Authentication for RADIUS??

This thread has been viewed 0 times
  • 1.  Persistent Authentication for RADIUS??

    Posted Mar 23, 2016 06:53 PM

    I'm using CPPM as a RADIUS Authentication source for managment of our Cisco ASA firewalls.

     

    I have a sevice which makes a RADIUS call to a one-time-password provider (SafeNet) and couples the response with AD-group membership to determine authentication/authorization.

     

    For the routed firewall, this works perfectly.

    The other firewall is transparent, and Cisco doesn't support their GUI (java application) login with OTP in transparent mode - the GUI authenticates 28 times just to get started!

     

    I'm thinking it would be really neat if CPPM could remember that I'd just been authenticated from my IP address to the firewall just seconds ago and simply re-authorize me rather than re-submit the RADIUS call to the OTP provider for each of the 28 requests. Something like caching for 60 seconds a particular host IP/ NAS IP authentication result.

     

    Anyone have a better idea? Or think this one is possible?



  • 2.  RE: Persistent Authentication for RADIUS??

    Posted Mar 23, 2016 06:53 PM

    veryone tell that I think CPPM is really cool and I want it to do everything!!?!



  • 3.  RE: Persistent Authentication for RADIUS??



  • 4.  RE: Persistent Authentication for RADIUS??

    Posted Mar 23, 2016 07:07 PM

    We are preparing to review our firewall choices - my Palo Alto sales team left me seriously underwhelmed while we were making the selection which got me the ASAs I'm using now.

     

    I'll have to try again.

     

    Menawhile I either need to work around the Cisco limitations or redesign the payment flow-

    Joy.