Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Single SSID OnBoarding authentication

This thread has been viewed 6 times
  • 1.  Single SSID OnBoarding authentication

    Posted May 04, 2017 07:33 PM

    Hi Forum,

     

    Can I have it configured where when a user provide EAP-PEAP credentials on thier smart device I redirecte them to the onboard page but not ask them to web authenticate again on the portal?



  • 2.  RE: Single SSID OnBoarding authentication

    EMPLOYEE
    Posted May 04, 2017 07:36 PM
    When using an Aruba controller, yes, you can use Aruba ASO.

    In most cases, dual SSID onboarding is recommended for security reasons.


  • 3.  RE: Single SSID OnBoarding authentication

    Posted May 04, 2017 07:37 PM

    I can probably google "what is aruba ASO"

    but can you elaborate?!



  • 4.  RE: Single SSID OnBoarding authentication



  • 5.  RE: Single SSID OnBoarding authentication

    Posted May 04, 2017 07:46 PM

    Thanks Tim, I was asking about something native without the need to idp. Cisco ISE does it by default when you onboard clients and I was curious to see if ClearPass has it as well out of the box.



  • 6.  RE: Single SSID OnBoarding authentication

    EMPLOYEE
    Posted May 04, 2017 07:48 PM
    This is completely native in ClearPass and the controller. No external IdP is required.


  • 7.  RE: Single SSID OnBoarding authentication

    Posted May 04, 2017 07:49 PM

    I should go watch that video.

     

    Thanks again.



  • 8.  RE: Single SSID OnBoarding authentication

    EMPLOYEE
    Posted May 04, 2017 07:51 PM
    The video covers ASO with third party apps. It can also be used internally with ClearPass SAML functions like Onboard. It's covered in the SAML TechNote.


  • 9.  RE: Single SSID OnBoarding authentication

    Posted May 04, 2017 08:04 PM

    Woow too many steps to get this simple task. I guess it is better than not having it at all. 

    I figured ClearPass is always a step ahead of ISE and though it might be a check box.



  • 10.  RE: Single SSID OnBoarding authentication

    EMPLOYEE
    Posted May 04, 2017 08:06 PM
    Do dual SSID onboarding ;)