Need an XID agent to read from an Aruba wireless access controller or a NAC system

rated by 0 users
This post has 11 Replies | 2 Followers

Top 100 Contributor
Posts 28
_Patrick_ Posted: 20 Apr 2012 6:54 AM

We currently have students that connect to the network with computers that are not joined to the domain.  They connect through an Aruba wireless system which authenticates through a RADIUS chain which includes a Bradford Network Access Control system and Microsoft IAS.  We put the Websense RADIUS agent in the chain, but since the authentication occurs at the network layer 2, the name/ip pair is not available during the authentication process.  Once the IAS confirms the username/password, it passes it back to Bradford which determines the VLAN and passes it back to Aruba which assigns the VLAN.  Once the machine has been assigned it's VLAN, it obtains it's IP through DHCP on that VLAN.  We need a websense XID agent that can read the username/ip pairs from Aruba, Bradford, or even a custom location.  Has anyone else come across this problem, and if so, what was your solution?

|
Top 10 Contributor
Posts 986
Trusted Users (MVP)

What is the back end authentication service, Active Directory?  You'll want to be integrating with that, not with your middle-men Aruba and Bradford. 

At the worst, manual authentication would do the trick although it's annoying.  Better case would be using WMI but that requires you to be using the Websense Content Gateway.

|
Top 100 Contributor
Posts 28

We do have a WCG is there a specific KB article you'd recommend for using WMI authentication on a WCG?

thanks,

|
Top 10 Contributor
Posts 986
Trusted Users (MVP)

I've never used it myself so unfortunately not, but I know many other people have it in use and seem to like it. Looking in the config it's actually called IWA (Integrated Windows Authentication).

IWA will allow you to have the browser do the authentication instead of trying to pull it from the backend somewhere.

|
Top 100 Contributor
Posts 28

IWA requires the machines to be joined to the domain -- thanks for checking though.  I think we're going to have to live with log on prompts or quick logging student names....

|
Top 10 Contributor
Posts 986
Trusted Users (MVP)

There's NTLM as well which may not require them to be on the domain

|
Top 10 Contributor
Posts 446
Trusted Users (MVP)

NTLM will still prompt the users, which is what he is trying to avoid.

|
Top 10 Contributor
Posts 446
Trusted Users (MVP)

Do you have RADIUS accounting enabled? Where in the chain did you put the WS radius agent?

From looking at the docs quickly, it seems that the WS Radius agent should be able to pick up the IP address from the accounting requests if accounting is enabled.

|
Top 100 Contributor
Posts 28

the chain looks like this:  aruba -- wsradius -- bradford nac -- IAS.   The IAS verifies the account and passes it back to bradford, bradford says, I recognize this user, put him in vlan xx, websense passes it to aruba who actually puts the machine in the vlan specified by the bradford system.  The machine then does DHCP on that VLAN to get it's IP address.  So the IP address is obtained after the radius chain is completed.

|
Top 10 Contributor
Posts 446
Trusted Users (MVP)

If I understand this correctly, then when the Aruba sends accounting updates to the IAS, then the WS Radius agent should be able to determine the IP address associated to the username that was authenticated on that same port. This assumes that you have configured the Aruba to send accounting information to IAS.

I have not tried this and am basing it purely on the documentation.

|
Top 100 Contributor
Posts 28

I'll research that a bit and reply back...thank you for the idea!

|
Top 100 Contributor
Posts 28

We pulled the WSRadius agents out of the authentication chain, but left them in the accounting chain, turned accounting on on the aruba controller and are now seeing username/ip combinations in the xid map on the filter service.  I'm no longer being prompted on my Iphone....good call mlpotgieter!

|
Page 1 of 1 (12 items) | RSS