I'm not sure about this, but 95 %, and ClearPass doesn't support MFA in RADIUS requests during network authentication.
I have seen a number of threads regarding the same and have also been discussing how to implement this internally at my company, but yet not found an answer.
------------------------------
Best Regards
Jonas Hammarbäck
MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security
Aranya AB
If you find my answer useful, consider giving kudos and/or mark as solution
------------------------------
Original Message:
Sent: May 25, 2025 07:30 PM
From: StrikerTS
Subject: Clearpass Radius Authentication to Okta
Yes, that is the guide we used to setup SAML for Okta. I'm not sure how I can use the SAML option any further since we don't have onboard. I was hoping to send the login attempts for our enterprise wifi auth through to Okta as well, but figure I would have to use Radius.
Original Message:
Sent: May 25, 2025 06:43 PM
From: ariyap
Subject: Clearpass Radius Authentication to Okta
so did you follow this procedure
Onboard and Okta (Configuration Guide: Onboard and Cloud Identity Providers)
------------------------------
If my post was useful accept solution and/or give kudos.
Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
Original Message:
Sent: May 23, 2025 12:22 PM
From: StrikerTS
Subject: Clearpass Radius Authentication to Okta
Hello All,
I have been trying to proof of concept sending wifi authentication requests through Radius to OKTA. I have found numerous articles about different setups but had difficulty replicating any of their steps with the differences in my environment. I believe I am missing something on the Clearpass side. Here is what I have:
Okta Side:
Radius app to receive requests, currently in use on other apps so I know it works.
Necessary firewall entries to allow udp traffic from the clearpass controllers.
CPPM:
An authentication source type RADIUS / RadSec.
The IP set for the Okta agent.
Tried a new UDP port and an existing one to check for traffic.
The secret which I have reset multiple times thinking I messed up.
A service looking for our broadcast SSID using the Okta Radius server for it's authentication source.
I have tried using multiple authentication methods including EAP-TLS, PAP, and EAP-TTLS, I have also tried with or without authorization.
Results:
Login attempts through wifi get - RADIUS No response from home server. I believe this means the communication failed. I checked the Okta server and see no logs generated at all, it's like the attempt never even got sent.
Am I missing a step or setting to actually send the radius packed OUT of CPPM to an external source? It almost feels like CPPM is trying to handle the request and not sending the request on to Okta.