Security

 View Only
  • 1.  Clearpass 802.1x with OTP

    Posted Jun 27, 2023 12:13 AM

    Hi,

    We have a customer who wants to use AD 802.1x auth with OTP (SMS or email). The OTP will be sent directly from clearpass without the aid of third party products.

    The flow will be like this: Enter AD username and password for 802.1x -> User gets default role which will redirects to captive portal to enter the OTP -> user enter the OTP sent via SMS/Email -> user gets the proper role

    Is this possible? 

    Thank you.



    ------------------------------
    AA
    ------------------------------


  • 2.  RE: Clearpass 802.1x with OTP

    Posted Jun 27, 2023 07:42 AM

    That may work, however you should not use AD username/password to do 802.1X authentication (PEAP) as it puts the user password at risk. Instead, use EAP-TLS or TEAP for secure access. Also, some clients don't handle captive portal on 802.1X networks very well. You may not get the captive portal automatically as the operating system may assume that 802.1X together with captive portal is an unusual combination.

    I would try to move away your customer from this idea.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Clearpass 802.1x with OTP

    Posted Jun 27, 2023 09:22 AM

    Hi Herman, Thank you for your input, i will inform the customer about it.

    In the meantime, could you explain how this would work?

    I see in this link https://www.linkedin.com/pulse/multifactor-authentication-aruba-clearpass-sushanth-mascarenhas/ that they use captive portal authentication before the OTP, but im not sure how this works with 802.1x before the OTP part. How do i get the CP to send the OTP without captive portal auth?



    ------------------------------
    AA
    ------------------------------



  • 4.  RE: Clearpass 802.1x with OTP

    Posted Jun 28, 2023 08:47 AM

    Don't combine 802.1X + MFA.  It is an awful user experience.... 




  • 5.  RE: Clearpass 802.1x with OTP

    Posted Jun 29, 2023 05:48 AM

    I agree, but the customer insisted ¯\_(ツ)_/¯

    Since this is a POC, i guess i will let them experience it first hand (if i could figure out how to do it..)



    ------------------------------
    AA
    ------------------------------



  • 6.  RE: Clearpass 802.1x with OTP

    Posted Jul 02, 2023 11:37 PM

    Additional question, is it possible to use email for the OTP? AFAIK only sms is possible



    ------------------------------
    AA
    ------------------------------