Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

How to set up a ClearPass policy to ensure BYOD devices don't get access to internal VLAN

This thread has been viewed 0 times
  • 1.  How to set up a ClearPass policy to ensure BYOD devices don't get access to internal VLAN

    Posted Apr 10, 2018 10:52 PM

    We have a ClearPass deployment where we have an internal VLAN with unlimited access to all RFC1918 addresses and a Guest VLAN which only provides access to the internet. 

     

    What we want to do is:

    - When a domain joined computer joins the "corp" SSID, the domain joined computer gets assigned the internal VLAN

    - When a non-domain joined laptop, phone, tablet owned by an employee joins the "corp" SSID, they get assigned the Guest VLAN, or a different VLAN of our choice.

    - People outside the organisation still connect to the Guest SSID and get the Guest VLAN - unchanged

     

    We don't want to set up a complicated BYOD configuration, all we want to achieve is the above. What's the simplest most effective way to ensure that if an employee joins their device to the corp SSID that they get assigned a different VLAN? 

     



  • 2.  RE: How to set up a ClearPass policy to ensure BYOD devices don't get access to internal VLAN

    EMPLOYEE
    Posted Apr 10, 2018 11:04 PM
    How will you be determining what is a corporate device vs personal?


  • 3.  RE: How to set up a ClearPass policy to ensure BYOD devices don't get access to internal VLAN

    Posted Apr 11, 2018 12:12 AM

    If they have a domain joined machine, we want ClearPass to recognise that it's joined to the domain and assign it the right VLAN. If the user tries to type in their domain\username and password credentials we want to make sure they can't get assigned the unrestricted VLAN. 



  • 4.  RE: How to set up a ClearPass policy to ensure BYOD devices don't get access to internal VLAN

    Posted Apr 11, 2018 05:16 PM

    I am open to any other ideas as well as long as it helps achieve the goal stated.



  • 5.  RE: How to set up a ClearPass policy to ensure BYOD devices don't get access to internal VLAN
    Best Answer

    EMPLOYEE
    Posted Apr 12, 2018 03:31 AM

    One option is doing Machine Authentication, where CPPM will check if the machine is in the domain. In this case, CPPM'll tag this authentication with the ROLE "Machine Authenticated". You can use this role in the Enforcement Profile to assign the computer to internal VLAN. In this case, you have to enable machine authentication in the supplicants.

    Other option is distribute certificates in coprporate computers and used them to authenticated corporate devices. You'll check this certificates in the authentication process and allow them to internal vlan.