Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

clearpass domain user login isse

This thread has been viewed 2 times
  • 1.  clearpass domain user login isse

    Posted Nov 10, 2015 08:49 AM

    hi,

    we have an cleapass joined to domain,

    we are checking if the user authentication only,

    domain user is successfully looged in and uathentciated,

    our issue when we try to loggoff that user and try to login again wirth different domain user !

    we are not able to authenticate that user, till we shut the port ion cisco switch and open it again,

     

    any help



  • 2.  RE: clearpass domain user login isse

    EMPLOYEE
    Posted Nov 10, 2015 08:52 AM

    Answer: you need to configure machine authentication on the workstation.

     

    If you are using 802.1x for authentication, that means the workstation has no connection to the domain until the user authenticates.  Even when the user authenticates via 802.1x, if the user's profile is not on the machine, the user cannot authenticate.  If you configure machine authentication, the workstation with authenticate as a machine and have a connection to the domain at the ctrl-alt-delete screen, so it can download the user's profile when the user logs in.

     



  • 3.  RE: clearpass domain user login isse

    EMPLOYEE
    Posted Nov 10, 2015 08:52 AM

    Answer: you need to configure machine authentication on the workstation.

     

    If you are using 802.1x for authentication, that means the workstation has no connection to the domain until the user authenticates.  Even when the user authenticates via 802.1x, if the user's profile is not on the machine, the user cannot authenticate.  If you configure machine authentication, the workstation with authenticate as a machine and have a connection to the domain at the ctrl-alt-delete screen, so it can download the user's profile when the user logs in.

     



  • 4.  RE: clearpass domain user login isse

    Posted Nov 10, 2015 05:37 PM

    i have already configured the workstation to accept user or machine authentication, and i unchecked the windows user name and password from the aythentiction tab,

     

    it works only when i shut and no shut the cisco port or when the macine restart again

     

     



  • 5.  RE: clearpass domain user login isse

    Posted Nov 12, 2015 09:58 AM

    A new Machine Authentication should happen when you log out and hit ctrl-alt-del to log in again.

    I'm assuming your workstation is Windows based. Added a screenshot of how the config should/might look on the machine itself.

     

    12.11.jpg

     

    For domain laptops you should keep the "Automatically use my windows" ... box checked.