Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

can we have unmanged switches to communicate wiith clearpass on controller untrusted port?

This thread has been viewed 0 times
  • 1.  can we have unmanged switches to communicate wiith clearpass on controller untrusted port?

    Posted Oct 24, 2016 07:26 AM

    I have a controller and Clearpass and we have most of the switches iis unmanged switches and we need to make802.1x and ongaurd healthchecks on users :

     

    so my question can we connect all unmanged switches on 1 untruusted port on a controlelr with AAA wired Global profile ??

     

    as we tried this but when connecting PC on unmanged switches it doesnt send any 8021x request .



  • 2.  RE: can we have unmanged switches to communicate wiith clearpass on controller untrusted port?

    EMPLOYEE
    Posted Oct 24, 2016 07:52 AM

    It would be a good idea if you draw a diagram of what you are trying to do.  It is not clear.



  • 3.  RE: can we have unmanged switches to communicate wiith clearpass on controller untrusted port?

    Posted Oct 24, 2016 09:49 AM
      |   view attached

    Here is teh Diagram we have Aruba controller with 1 port configured with Wired AAA and untrusted and we have unmanger switch connected to it with multiple useres where we need each of them to dod full 802.1x and health check with ongaurd,we did this scnario but no 802.1x request sent when connecting the unmangerd switch so what is teh solvent



  • 4.  RE: can we have unmanged switches to communicate wiith clearpass on controller untrusted port?

    EMPLOYEE
    Posted Oct 24, 2016 10:51 AM

    What would be the purpose of doing wired 802.1x?  802.1x or EAPOL frames are link-local which mean the first switch that sees a 802.1x frame has to do something with it or drop it.  So if you put a switch between your wired clients and another switch doing 802.1x, the second switch (the controller, I guess), will never see the 802.1x frames.  Are you working with a ClearPass reseller on this design?