Wired Intelligent Edge (Campus Switching and Routing)

Reply
Occasional Contributor II

Config for 5400 series with NAC

Hi all,

I have some 5400 switches I’m going to use with certificate based NAC. I believe there is a procedure to link the switch with Clearpass and then configure to check for a certificate when a port is activated / plugged into?

So do you just need to give the switch a valid certificate from your CA? Can it contain multiple certificates from different CAs?

Any good links to help config this from Clearpass / switch end?

Thanks
Guru Elite

Re: Config for 5400 series with NAC

Take a look at the ClearPass Solution Guide for Wired Policy Enforcement.

| Tim Cappalli | Aruba Security | @timcappalli | timcappalli.me |

NOTE: Answers and views expressed by me on this forum are my own and not necessarily the position of Aruba or Hewlett Packard Enterprise.
Highlighted
Occasional Contributor II

Re: Config for 5400 series with NAC

Thanks Tim,

Just at a high level for my understanding:

Clearpass - switch is added as a device within here and a policy ready for user upon successful 802.1x authentication?

On the switch - valid certificate from our CA and some config to perform checks for each port?

Can I disable the checks on certain ports?
Can I have multiple certificates on my switch to account for people with different CA certs?

Thanks
Guru Elite

Re: Config for 5400 series with NAC

The switch is not involved in the EAP transaction beyond encapsulating it into a RADIUS request.

| Tim Cappalli | Aruba Security | @timcappalli | timcappalli.me |

NOTE: Answers and views expressed by me on this forum are my own and not necessarily the position of Aruba or Hewlett Packard Enterprise.
Occasional Contributor II

Re: Config for 5400 series with NAC

Thanks Tim
Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: