Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Best way to diferentiate between Corporate and Personal Smart Phones?

This thread has been viewed 0 times
  • 1.  Best way to diferentiate between Corporate and Personal Smart Phones?

    Posted Nov 02, 2016 04:05 PM

    So how do you guys do it? Best way to diferentiate between Corporate and Personal Smart Phones using Clearpass with Active Directory?

     

    aaannndddd..... GO!!!



  • 2.  RE: Best way to diferentiate between Corporate and Personal Smart Phones?

    EMPLOYEE
    Posted Nov 02, 2016 04:07 PM
    Are you using an MDM for either classification of devices?


  • 3.  RE: Best way to diferentiate between Corporate and Personal Smart Phones?

    Posted Nov 02, 2016 04:13 PM

    Hiya Cappi! Negative, the client does not have an MDM as there are approximately 80 or so Android phones.

     

    So was wondering about other alternatives, possibly with AD/LDAP  queries?



  • 4.  RE: Best way to diferentiate between Corporate and Personal Smart Phones?

    EMPLOYEE
    Posted Nov 02, 2016 04:22 PM
    If you're not using an MDM, you'd have to leverage SHLs or Guest Device
    Repository with MAC address to identify them. Just keep in mind, MAC address
    can be spoofed, so you'll want to use the profile conflict detection
    mechanisms with this.



    One other alternative is to issue certificates to the corporate devices via
    Onboard or an external CA.


  • 5.  RE: Best way to diferentiate between Corporate and Personal Smart Phones?

    Posted Nov 02, 2016 04:30 PM

    SHLs?

     

     



  • 6.  RE: Best way to diferentiate between Corporate and Personal Smart Phones?

    EMPLOYEE
    Posted Nov 03, 2016 08:13 AM

    Static host lists in ClearPass or a list of corporate mac addresses.



  • 7.  RE: Best way to diferentiate between Corporate and Personal Smart Phones?

    Posted Nov 03, 2016 03:14 PM

    There are waaaaaaay too many acronyms in our line of work :-)

     

    But yeah, I think that is the direction we are going to go. Thanks for the assistance gang!