That may work, however you should not use AD username/password to do 802.1X authentication (PEAP) as it puts the user password at risk. Instead, use EAP-TLS or TEAP for secure access. Also, some clients don't handle captive portal on 802.1X networks very well. You may not get the captive portal automatically as the operating system may assume that 802.1X together with captive portal is an unusual combination.
I would try to move away your customer from this idea.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Jun 27, 2023 12:13 AM
From: Aria_A
Subject: Clearpass 802.1x with OTP
Hi,
We have a customer who wants to use AD 802.1x auth with OTP (SMS or email). The OTP will be sent directly from clearpass without the aid of third party products.
The flow will be like this: Enter AD username and password for 802.1x -> User gets default role which will redirects to captive portal to enter the OTP -> user enter the OTP sent via SMS/Email -> user gets the proper role
Is this possible?
Thank you.
------------------------------
AA
------------------------------