Security

last person joined: 20 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass to identify if the devices is of the company or not

This thread has been viewed 1 times
  • 1.  Clearpass to identify if the devices is of the company or not

    Posted Aug 22, 2015 10:43 AM

    is this possible?

    This client would like to identify if the device belong to the company or not and then do an action for example if the laptop is from the company give him all the privileges, if its not then no.

     

    I know you can  identify user, and if the user is using a laptop and also if the same user is using a smatphone, and putting differnet roles to both of them

     

    But what about if i got this situation

    The company has a few company smartphones, that belong to them, and they would like to identify if the:

    smartphone belong to the compnay

    Who is using it

    And depending on both take an action i mean if it belong to the company and its a high executive, give him all access.

    If its a smartphone of the company and belong to sales, give him this access

     

    if it belong to the user, and he is a high executive, give him this access

    and so on.

     

    Is this possible?



  • 2.  RE: Clearpass to identify if the devices is of the company or not
    Best Answer

    EMPLOYEE
    Posted Aug 22, 2015 10:59 AM

    They can check for machine authentication for the laptops to check domain membership for windows devices. For mobile devices, they can either onboard them, or put the Mac addresses of company owned mobile devices into a static host list and then check the calling-station-Id (Mac addresses) of devices to see if they belong to that static host list.



  • 3.  RE: Clearpass to identify if the devices is of the company or not
    Best Answer

    EMPLOYEE
    Posted Aug 22, 2015 11:03 AM
    Certificates would be the best route. You can use a different CA for corporate device.


    Thanks,
    Tim


  • 4.  RE: Clearpass to identify if the devices is of the company or not

    Posted Aug 22, 2015 11:06 AM

    Thank you guys!!



  • 5.  RE: Clearpass to identify if the devices is of the company or not

    Posted Aug 24, 2015 03:57 PM

    Tim Question

    When you say use a differnt CA for corporate

    Are you suggesting of having one CA for coporate devices and one CA for non corporate devices?

     

    Cheers

    Carlos



  • 6.  RE: Clearpass to identify if the devices is of the company or not

    EMPLOYEE
    Posted Aug 24, 2015 04:02 PM
    Yes that's a common scenario. You could either use two different Onboard CAs or an Onboard CA for BYOD and an ADCS CA for corporate.


    Thanks,
    Tim