Security

 View Only
  • 1.  ClearPass 802.1x authentication AD necessary to Join domain or not?

    Posted Jun 12, 2023 10:09 PM
    I have a question: when implementing 802.1x authentication in AD with ClearPass, is it necessary to join the domain or not?
     
    Because we try to create an authentication source by using clearpass to not join Doamin and mapping to tacac+ authen service, and we authen successfully, I'm wondering why we need to use clearpass to join AD.


  • 2.  RE: ClearPass 802.1x authentication AD necessary to Join domain or not?

    Posted Jun 12, 2023 10:14 PM

    if you want to use AD as an authentication source then ClearPass needs to join the domain to be able to authenticate users and provide further authorisation.

    For TACACS, you might be using local auth source which is the local user db for authentication.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: ClearPass 802.1x authentication AD necessary to Join domain or not?

    Posted Jun 12, 2023 10:33 PM

    But I create authentication AD source by not join domain and authentication it working so I wondering why need to join domain. I will try again with user authentication on switch.




  • 4.  RE: ClearPass 802.1x authentication AD necessary to Join domain or not?

    Posted Jun 13, 2023 07:23 AM

    You don´t need to join Clearpass to Domain. 
    You just need a valid signed Certificate for Clearpass for the EAP Authentication and if you want to authorize you need a LDAP(S) Connection to the Domain.




  • 5.  RE: ClearPass 802.1x authentication AD necessary to Join domain or not?

    Posted Jun 15, 2023 10:45 PM

    Hi @AP-e172d8  I create authentication source type AD and test authentication by not join domain it like you said client cannot authentication.

    Hi @AH71 

    You mean just create authentication source type LDAP to domain, right?

    And I have question what difference about authentication source AD and LDAP?

    Which one should I choose?




  • 6.  RE: ClearPass 802.1x authentication AD necessary to Join domain or not?

    Posted Jun 16, 2023 02:37 AM

    Hello,

    Joining AD domain is only required when using PEAP (not recommended anymore !!). If using EAP-TLS it is not needed

    Kind regards

    Christian Chautems




  • 7.  RE: ClearPass 802.1x authentication AD necessary to Join domain or not?

    Posted Jun 16, 2023 03:03 AM

    Sorry but this is not true. You can also use PEAP with inner EAP-TLS which is common and recommended. 
    If you are using PEAP with inner MSChapv2, you will have troubles in future because beginning of Windows11 it doesn´t work anymore.

    @tt23

    Use LDAP, because you are more flexible and you dont need to join Clearpass. It´s just a Protocol to retrieve Authorization for Computer Object in a Active Directory.




  • 8.  RE: ClearPass 802.1x authentication AD necessary to Join domain or not?

    Posted Jun 28, 2023 10:33 AM

    Joining the AD domain is only needed if you need to do MSCHAPv2 authentication against the AD domain. Which in practice comes down to PEAP-MSCHAPv2, which is deprecated and should be avoided whenever possible.

    So you should not need to join the AD domain, unless you ignore the recommendations to phase out MS-CHAPv2.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------