Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

experience with token service intergration

This thread has been viewed 0 times
  • 1.  experience with token service intergration

    Posted May 04, 2012 02:51 AM

    does anyone here have a token service (i.e. RSA, safeword) intergrated with their aruba controller for dot1x? how have you set it up? an alternative to username and password or an adition? does it require extra software on the client machine?



  • 2.  RE: experience with token service intergration

    EMPLOYEE
    Posted May 04, 2012 06:01 AM

    @boneyard wrote:

    does anyone here have a token service (i.e. RSA, safeword) intergrated with their aruba controller for dot1x? how have you set it up? an alternative to username and password or an adition? does it require extra software on the client machine?


    the RSA server has a built in radius server.  You need to Terminate the 802.1x session on the Aruba controller and use EAP-GTC and enable token caching for the best results.  Of course Windows devices will need to install a supplicant like the EAP-GTC shim.  All other Operating Systems Support GTC out the box, however.

     



  • 3.  RE: experience with token service intergration

    Posted May 07, 2012 06:55 AM

    thanks cjoseph. i asume you have to choose between either username/password or token? you can't do username/password and token at the same time?

     

    could you for example do username/password first and do token via captive portal later? or the other way around?



  • 4.  RE: experience with token service intergration
    Best Answer

    EMPLOYEE
    Posted May 07, 2012 07:21 AM

    @boneyard wrote:

    thanks cjoseph. i asume you have to choose between either username/password or token? you can't do username/password and token at the same time?

     

    could you for example do username/password first and do token via captive portal later? or the other way around?



    Yes, you have to choose.  You can also do the Captive Portal scenario that you mentioned.

     



  • 5.  RE: experience with token service intergration

    Posted May 09, 2012 08:28 AM

    totally clear, thank you.