Yes TEAP works great in my experience. It doesn't necessarily "improve" auth from a properly deployed EAP-TLS or PEAP deployment but it does add the additional "Factor" and visibility into both machine and user states.
If you use TEAP with PEAP inner method you will still see the machine auth cache expired issue. You would use TLS as an inner method and use certificates instead for both machine and user auth.
Original Message:
Sent: Feb 08, 2024 03:26 PM
From: MatazaNz
Subject: ClearPass: How are you organising your services?
@jonas.hammarback @mholden
Thank you both. This is valuable insight. Seems like my predecessor didn't do us any favours they way he has set this up. A lot of the services are relying on ClearPass to match the device prior to the authentication phase (e.g. Device source equals Intune/JamfPro, etc). This, to me, seems unreliable. Instead, this should be evaluated during authorisation, as you will then have all information required for the device or user, since that will be contained in the authentication request, or can be queried easily. Querying during the service filter seems quite difficult, which is where I've been running into diffculties.
As an aside, have either of you used EAP-TEAP? If so, what was the experience? Did it improve user authentication, especially in cases where the machine authentication cache has expired for that particular device? For context, the student users rarely log out of their managed laptops, let along restart them. Bad practice, but they are not my responsibility, unfortunately. I have proposed TEAP to streamline the process, plus revising their services to better meet best practices.
Original Message:
Sent: Feb 08, 2024 09:48 AM
From: jonas.hammarback
Subject: ClearPass: How are you organising your services?
In general terms I usually implements customer with as few services as possible and try to have the one role mapping policy for all 802.1x services and one role mapping policy for all MAC auth services.
In most cases the base services are:
- 802.1x wireless
- 802.1x wired
- MAC auth wired
- Guest registration (Radius)
- Guest MAC auth
- Wireless MPSK
For 802.1x I usually have all needed authentication methods in the same service.
If you have a distributed environment with local ClearPass servers in several countries and AD domain controllers in the same sites, you also need separate LDAP sources for each of the sites, and also a separate 802.1x service for each country with the LDAP source for this specific country. Otherwise you can't control how ClearPass connects to LDAP.
In networks with multiple switch families or brands you may also have to implement services with the specific CoA settings in the Profiling tab for each switch type..
------------------------------
Best Regards
Jonas Hammarbäck
MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
Aranya AB
If you find my answer useful, consider giving kudos and/or mark as solution