Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Certificate based authentication

This thread has been viewed 4 times
  • 1.  Certificate based authentication

    Posted Dec 10, 2015 05:01 PM

    Currently we are running Clearpass with mobility controllers at our branch offices.  We are using PEAP for the company owned laptops to connect.  We require an active directory username/pass in order to connect.  The problem is, personal devices are able to connect to the company wifi as long as the employee has a username/pass.  we are looking for a way for the laptops to connect (cert maybe?) AND company smart devices but not personal devices to connect (laptop or smart device).  also dont want the employees to have to enter their creds.  We have tested Airwatch/Clearpass integration and only allowed Airwatch enrolled smart devices to connect, however we are moving away from Airwatch so this wont work.  we have also tested Onboarding but that requires the user to enter username/pass??  is there a way for the users to conveniently connect but securely???



  • 2.  RE: Certificate based authentication

    EMPLOYEE
    Posted Dec 10, 2015 05:03 PM

    Onboarding requires an Initial username and password.  After that, the certificate can be used.

     



  • 3.  RE: Certificate based authentication

    Posted Dec 11, 2015 11:18 AM

    we come to terms and are ok with an intitial prompt for username/pass but how can we avoid AD users connecting with their personal devices?  currently, we have the provisioning profile configured for an allowed AD group.



  • 4.  RE: Certificate based authentication

    EMPLOYEE
    Posted Dec 11, 2015 01:16 PM
    You would need some type of authorization source in ClearPass to determine
    corporate vs personal.



    Some options:

    - Manual endpoint updates

    - Information from MDM

    - SQL connection to asset database


  • 5.  RE: Certificate based authentication

    EMPLOYEE
    Posted Dec 10, 2015 05:03 PM

    You can use machine authentication on the laptop side which will only allow devices on that authenticate with their machine account to the domain.

     

    For mobile devices, you still need an authoritative source of what is corporate owned and what is not. Are you moving to another MDM?



  • 6.  RE: Certificate based authentication

    Posted Dec 10, 2015 05:06 PM

    Yes, MS Intune



  • 7.  RE: Certificate based authentication

    EMPLOYEE
    Posted Dec 10, 2015 05:07 PM

    OK, then you can manually mark the corporate devices in the endpoints repository or possibly export a list out of InTune.



  • 8.  RE: Certificate based authentication

    Posted Dec 10, 2015 05:08 PM

    we were thinking that but we would have to touch every device.



  • 9.  RE: Certificate based authentication

    EMPLOYEE
    Posted Dec 10, 2015 05:12 PM
    How do the corporate devices get distributed?


  • 10.  RE: Certificate based authentication

    Posted Dec 11, 2015 10:12 AM

    we push profiles via Airwatch