Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
Authentication and Authorization Architecture and Flow
Policy Manager divides the architecture of authentication and authorization into the following three components:
Policy Manager initiates the authentication handshake by sending available methods in a priority order until the client accepts a method or until the client rejects the last method with the following possible outcomes:
Successful negotiation returns a method, which is used to authenticate the client against the authentication source.
Where no method is specified (for example, for unmanageable devices), Policy Manager passes the request to the next configured policy component for this service.
Policy Manager rejects the connection.
|
An authentication method is configurable only for some service types. For more information, see Configuring Services Manually or with Wizards. All 802.1X 802.1X is an IEEE standard for port-based network access control designed to enhance 802.11 WLAN security. 802.1X provides an authentication framework that allows a user to be authenticated by a central authority. wired and wireless services have an associated authentication method. |
In Policy Manager, an authentication source is the identity store (Active Directory Microsoft Active Directory. The directory server that stores information about a variety of things, such as organizations, sites, systems, users, shares, and other network objects or components. It also provides authentication and authorization mechanisms, and a framework within which related services can be deployed., LDAP Lightweight Directory Access Protocol. LDAP is a communication protocol that provides the ability to access and maintain distributed directory information services over a network. directory, SQL DB, token server, etc.) against which users and devices are authenticated.
Policy Manager first tests whether the connecting entity (the device or user) is present in the ordered list of configured authentication sources.
Policy Manager looks for the device or user by executing the first filter associated with the authentication source. After the device or user is found, Policy Managerthen authenticates this entity against this authentication source. The flow is as follows:
On successful authentication, Policy Manager moves on to the next stage of policy evaluation, which collects role mapping attributes from the authorization sources.
Where no authentication source is specified (for example, for unmanageable devices), Policy Manager passes the request to the next configured policy component for this service.
If Policy Manager does not find the connecting entity in any of the configured authentication sources, it rejects the request.
|
|
Starting with the ClearPass 6.11.0 release, the database system also uses port 5433 in addition to port 5432. Users should be aware that ports 5433 and 5432 must both be open when attempting to remotely connect to the Policy Manager database. |
After Policy Manager successfully authenticates the user or device against an authentication source, it retrieves role-mapping attributes from each of the authorization sources configured for that authentication source.
It also, optionally, can retrieve attributes from authorization sources configured for the service.
Authentication and Authorization Flow of Control
The flow of control for authentication takes the following components in sequence:
Figure 1 Authentication and Authorization Flow of Control