Security

 View Only
Expand all | Collapse all

Azure AD as ClearPass Authentication Source for TACACS+

This thread has been viewed 44 times
  • 1.  Azure AD as ClearPass Authentication Source for TACACS+

    Posted 8 days ago

    what is the requirement from Clearpass & AZURE AD to control managment of Network Devices with TACACS+?



    -------------------------------------------


  • 2.  RE: Azure AD as ClearPass Authentication Source for TACACS+

    Posted 8 days ago

    As far as I know, you cannot use Entra ID as an authentication source for TACACS+. Instead, you can create local user accounts in the ClearPass internal database and use those for TACACS+ authentication.



    ------------------------------
    Marcel Koedijk | MVP Expert 2024 | ACEP | ACMP | ACCP | ACDP | Ekahau ECSE | Not an HPE Employee | Opinions are my own
    ------------------------------



  • 3.  RE: Azure AD as ClearPass Authentication Source for TACACS+

    Posted 8 days ago

    thanks for your reply 

    What are the requirements for SAML and do I need onboard licenses?

    -------------------------------------------



  • 4.  RE: Azure AD as ClearPass Authentication Source for TACACS+
    Best Answer

    Posted 7 days ago

    You can't use SAML with TACACS+. TACACS+ is not a browser based application. Entra ID supports SAML natively, there is no need for ClearPass in that flow.

    -------------------------------------------



  • 5.  RE: Azure AD as ClearPass Authentication Source for TACACS+

    Posted 7 days ago

    thanks for your reply 

    The problem is how to manage switches in that is scenario?

    -------------------------------------------



  • 6.  RE: Azure AD as ClearPass Authentication Source for TACACS+

    Posted 7 days ago

    What do you mean? What scenario? Is there no on-prem AD sync? This is an Entra only customer?

    -------------------------------------------



  • 7.  RE: Azure AD as ClearPass Authentication Source for TACACS+

    Posted 7 days ago

    Yes Entra only

    -------------------------------------------



  • 8.  RE: Azure AD as ClearPass Authentication Source for TACACS+

    Posted 7 days ago

    You don't. You use SSH keypairs (certificates) or some other user database.

    -------------------------------------------



  • 9.  RE: Azure AD as ClearPass Authentication Source for TACACS+

    Posted 7 days ago

    Certificates signed From Public CA?

    -------------------------------------------



  • 10.  RE: Azure AD as ClearPass Authentication Source for TACACS+

    Posted 7 days ago
    No, corporate CA. Internal proper 3 tier offline root PKI. Or a PKIaaS provider.





  • 11.  RE: Azure AD as ClearPass Authentication Source for TACACS+

    Posted 7 days ago

    Use ClearPass Azure AD Secure Client / OAuth 2.0 / Graph API with Radius can be solve issue or same also?

    -------------------------------------------



  • 12.  RE: Azure AD as ClearPass Authentication Source for TACACS+

    Posted 7 days ago

    You can create management accounts in the local clearpass database and use that as authentication source in your tacacs+ configuration for switch management.


    C2-Vertrouwelijk