Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Location specific authentication servers

This thread has been viewed 12 times
  • 1.  Location specific authentication servers

    Posted 12 days ago

    Is it possible to select an authentication server based on the controller used?

    I have a 4 node CPPM cluster, authenticating to a primary and backup AD controller on our main campus. One of those nodes is on a remote campus, and I'd like to have it use a local AD controller rather than authenticating across the WAN.

    I can create a unique authentication server, and I can create a unique service to use it based on the NAS ID, but is there a better and less manual way?

    This is for eduroam, so switching from passwords to certificates is not an option.



  • 2.  RE: Location specific authentication servers

    EMPLOYEE
    Posted 12 days ago

    The topic "Adding a Password Server" is what I think you are after.

    https://www.arubanetworks.com/techdocs/ClearPass/6.12/PolicyManager/Content/CPPM_UserGuide/Admin/ServerConfig_editsystemtab.htm#B926210353



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: Location specific authentication servers

    Posted 12 days ago

    Thanks Carson. That will take care of it for authentications.

    Now if I understand correctly, the AD domain connection is only used for MSCHAPV2 logins. All the attributes are pulled using LDAP from the AD server(s) in the authentication source. I think I can do some geo-dns hacks to make that work.

    Friday is funday. :)




  • 4.  RE: Location specific authentication servers
    Best Answer

    EMPLOYEE
    Posted 12 days ago

    Set your Auth Source primary target to the domain name rather than a specific DC, DNS should return a result based on the configured site.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: Location specific authentication servers

    Posted 12 days ago

    Well that's simply too logical.

    Thanks!

    Andrew