Security

last person joined: 21 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

How to Configure PEF

This thread has been viewed 2 times
  • 1.  How to Configure PEF

    Posted Aug 21, 2013 05:41 AM

    The main purpose of the license is to be able to blacklist MAC addresses and user devices from accessing the wireless
    network as their have a large volume of users using their own PDAs and Smart Phones for personal purposes. please guide me how to create a policy to achieve the above goals.

     

     



  • 2.  RE: How to Configure PEF

    Posted Aug 21, 2013 07:16 AM

    It would be better to specify which devices are allowed on your network. You will never be able to block everything as every thime a user brings a new unknown device to the network, they will be allowed in. If all your allowed devices are a member of your AD domain for example, you can use this as authentication on the network. Another example is to whitelist all KNOWN ALLOWED mac addresses.



  • 3.  RE: How to Configure PEF

    Posted Aug 21, 2013 08:15 AM

    Actually I want to allow only employee with the know device that must be registered before accessing my wireless network and restrict all other unknown users and devices. Please give me suitable and easy solution.



  • 4.  RE: How to Configure PEF

    Posted Aug 21, 2013 08:21 AM

    So all employees are using BYOD devices?

    If you need to decide which devices are allowed in. You could make a record of the MAC address for all the allowed devices to your whitelist and then enter them into your Controller. Another sollution, if you are for example only accepting PC's and you have a Windows Certificate server, you can install certificates on the users laptops and use that for 802.1x authentication



  • 5.  RE: How to Configure PEF

    Posted Aug 21, 2013 09:09 AM

    i will consider the first solution because we don't have any certificate or authentication server. but as per your solution that i should make record of all device MAC empolyee devices.,but i don't know how to create a whitelist and also tell me about the  mac-address authentication using internal database please.