Security

 View Only
last person joined: 10 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass allow only domain computers 802.1x Wireless / Wired services

This thread has been viewed 28 times
  • 1.  Clearpass allow only domain computers 802.1x Wireless / Wired services

    Posted Dec 02, 2022 12:39 PM
    Hi!
    I know ClearPass allows to configure a rule that permits only domain computers connect to the corporate network via Wired / Wireless.
    I have read several posts about this subjet but I don´t understand the way to do it.
    Please, Is there any guide or post which explains how to check if an endpoint belongs to the domain to allow it with a valid domain user credential to connect to the network? 
    Is there an easy way to achieve this target?
    Thank you in advance.
    Regards.


  • 2.  RE: Clearpass allow only domain computers 802.1x Wireless / Wired services

    Posted Dec 02, 2022 03:59 PM
    Authorization[AD]: memberOf CONTAINS "Domain Computers"


  • 3.  RE: Clearpass allow only domain computers 802.1x Wireless / Wired services

    EMPLOYEE
    Posted Dec 02, 2022 09:45 PM
    are you trying to do machine authentication? if so you can just match on Tips role = [Machine Authentication]



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 4.  RE: Clearpass allow only domain computers 802.1x Wireless / Wired services

    Posted Dec 03, 2022 12:17 PM
    Hi ariyap.
    Thank you for your answer.
    You must take into account that our customer use EAP-PEAP and I think it's no possible to do machine authentication with that protocol. Maybe I'm wrong.
    The only thing I want to check is the computer belongs to the domain and I'm not sure if machine authentication will be an option in this scenario.
    What do you think about it?
    Regards


  • 5.  RE: Clearpass allow only domain computers 802.1x Wireless / Wired services

    Posted Dec 03, 2022 12:58 PM
    Yes you can do machine authentication using PEAP. Set your supplicant to “Computer Authentication” or “user or Computer Authentication”




  • 6.  RE: Clearpass allow only domain computers 802.1x Wireless / Wired services

    Posted Dec 03, 2022 02:24 PM
    Hi ahollifield.
    Thank you for the clarification.
    The supplicant is configured as "user or computer authentication". So adding the condition  Authorization[AD]: memberOf CONTAINS "Domain Computers" in the rule it should be work fine, isn't it?

    Thank you so much!
    Regards



  • 7.  RE: Clearpass allow only domain computers 802.1x Wireless / Wired services

    Posted Dec 03, 2022 02:58 PM
    Depends. You should also match against role Machine Authenticated




  • 8.  RE: Clearpass allow only domain computers 802.1x Wireless / Wired services

    Posted Dec 03, 2022 12:07 PM
    Thank you so much for the answer!
    I will try it on Monday.
    Regards!


  • 9.  RE: Clearpass allow only domain computers 802.1x Wireless / Wired services

    EMPLOYEE
    Posted Dec 03, 2022 07:35 PM
    yes as ahollifield, mentioned yo can have machine auth with PEAP authentication



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 10.  RE: Clearpass allow only domain computers 802.1x Wireless / Wired services

    Posted Dec 05, 2022 05:14 AM
    Hi!
    Yes I can see with PEAP machine authentication works fine but I have difficulties to link the Machine authenticated role with the AD where are located the domain computers. I have did it with the user roles and the AD groups which they belong to, but it's not easy for me to do the same with the domain computers and Machine authenticated.
    Maybe my focus is wrong to achieve this goal.
    Thank you.
    Regards


  • 11.  RE: Clearpass allow only domain computers 802.1x Wireless / Wired services

    Posted Dec 05, 2022 01:37 PM
    Hi.
    I just realized that the Machine Authenticated role appears doing an authentication with the windows supplicant set as "user or Computer Authentication" as you said. In that case I think it is enough to validate the role Machine authenticated.
    Sorry, but really it's hard to understand for me.
    Thank you so much.
    Regards.