Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Device MAC address authentication to SSID

This thread has been viewed 5 times
  • 1.  Device MAC address authentication to SSID

    Posted Jan 09, 2013 03:38 PM

    Aruba OS is 6.1.3.4

    I have PEF.

    I am implementing about 111  Windows CE wireless devices. I would like them to access the new SSID that I built using MAC address authentication, instead of WEP password/key.

    What are the steps to do this?

    Currently the SSID is using WEP and the SSID is not being broadcast.

    I found bits and pieces in the User Guide to try and accomplish this but no luck.

    Any help would be appreciated. thanks.



  • 2.  RE: Device MAC address authentication to SSID
    Best Answer

    Posted Jan 09, 2013 10:53 PM

    You can use internaldb inside controller for registering mac address

    - Populate InternalDB with MAC of client

    - Create/edit AAA profile "default-MAC-auth"

    - Set the mac-authenticated role inside "default-MAC-auth" to whatever you need

    - Create new AP Group, using tthis AAA profile

    - For SSID try using open auth first

    - Provision the AP and try the network


    Goodluck

     

    Checkout :

    https://arubanetworkskb.secure.force.com/pkb/articles/HowTo/R-1126

    https://arubanetworkskb.secure.force.com/pkb/articles/HowTo/R-399



  • 3.  RE: Device MAC address authentication to SSID

    Posted Jan 11, 2013 10:45 AM

    I got this to work. I think it was the OPEN authentication that did the trick. However I am changing gears due to the fact that I would have to enter 111 devices into the internal database (more mgmt work).  SOOO, I am persuing User Derivation Rules using the first six characters of the mac address to further qualify their  connection to the specific SSID. Its not working as planned either but thats another post. Thanks for input.