Skip main navigation (Press Enter).
Log in
Toggle navigation
Log in
Home
Discussion Forum
Support
Documentation Portal
Support Knowledge Base
HPE Networking Support Portal
HPE Aruba Networking Central Status
Live + Virtual Events
Webinar Archive
Upcoming Events
News
Technical Blog
ACEX Hall of Fame
MVP Program
Become a Member
Security
×
Community Home
Discussion
63.3K
Members
2.5K
View Only
Back to Library
CPPM 6.7 using Fortinet-Group-Name attribute- factibility
Kudos
Feb 02, 2021 02:22 AM
jroman
I need to configure 802.1x PEAP authentication using CLEARPASS as NAC and Fortigate100D as NAD. take in consideration that fortigate 100D works as a WLC for FortiAP431F (Tunnel mode), so user authentication and authorization should be done from SSID created on fortiAP. but I want only users belonging to specific group to have access to the network. Users and groups are stored on CLEARPASS as an authentication source through Active directory.
I was researching and found the following fortinet's link that makes me an idea.
https://kb.fortinet.com/kb/documentLink.do?externalID=FD36464
It expect that AVP being provided by NAS server (RADIUS server) in Access-Accept (if user pass authentication).
And then FortiGate compare string-by-string what is in group match config and what he got from RADIUS server. If it matches perfectly (100% match) then the user is considered as member of that group in FORTIGATE device, Then it could apply a firewall policy on fortinet based on Source group name.
could the test work with clearpass and fortiAP with those advices?
I attach two screens of planning for clearpass, in enforcement and profiles
please, your advice or support if it is possible or not.
Statistics
0 Favorited
27 Views
3 Files
0 Shares
12 Downloads
Attachment(s)
Download All
enforcement_policy_CPPM.jpg
79 KB
1 version
Uploaded - Feb 02, 2021
Download
enforcement_profile_CPPM.JPG
43 KB
1 version
Uploaded - Feb 02, 2021
Download
FORTIGATE_GROUP_NAME.jpg
68 KB
1 version
Uploaded - Feb 02, 2021
Download
Download Document
Please accept the terms of the copyright associated with this attachment before downloading it. Click the link below to read the terms.
Accept
Related Entries and Links
No Related Resource entered.
Copyright 2024. All rights reserved.
Powered by Higher Logic