Security

last person joined: 13 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

SSID with Secure authentication and guest authentication

This thread has been viewed 0 times
  • 1.  SSID with Secure authentication and guest authentication

    Posted Oct 02, 2014 01:19 PM
    Would it be possible to have a single SSID configured to handle secure wpa2 authentication as well as open authentication to redirect guests to a captive portal?


  • 2.  RE: SSID with Secure authentication and guest authentication

    Posted Oct 02, 2014 01:46 PM
    No, what you can have is a 802.1X that could redirect user to a captive portal but this will fm happen after the username/password has been provided.


  • 3.  RE: SSID with Secure authentication and guest authentication

    EMPLOYEE
    Posted Oct 02, 2014 01:57 PM

    PEAP-Public is an option.

     

    Instead of a PSK, the user would enter the key as both the username and password. You could then direct them to a captive portal to register.

     

    It's not open, but is a public access method with enables their traffic to be encrypted.

     

    Otherwise you will need to use two SSIDs.

     

     



  • 4.  RE: SSID with Secure authentication and guest authentication

    Posted Oct 02, 2014 02:32 PM

    Thank you for the responses!  I did want to further expand on what we are trying to accomplish as my first post was rather rushed.  Essentially, we want users to connect to a single SSID and use ClearPass as the decision maker as to whether or not they will utilize EAP-TLS (with certificates) or be sent to a captive portal if they do not to register as a guest user (or login with AD credentials).

     

    From what I have seen, I believe we would still need multiple SSID's, but I wanted to confirm that is the case.



  • 5.  RE: SSID with Secure authentication and guest authentication
    Best Answer

    EMPLOYEE
    Posted Oct 02, 2014 02:40 PM

    Yes, EAP authentication would need to happen before ClearPass can make a decision. Sounds like two SSIDs will be necessary for your environments.