Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Mac Cache

This thread has been viewed 4 times
  • 1.  Mac Cache

    Posted Dec 14, 2014 11:24 PM

    I’ve got a guest SSID setup on a controller redirecting to a webpage on Clearpass. I have Mac Caching enabled, well at least I thought I did. The Mac are not registering/populating the database so something must be a miss. Any advice on where to look or clear cut instructions for setting that up?

     

    Thxs



  • 2.  RE: Mac Cache

    Posted Dec 14, 2014 11:39 PM

    What I suggest you do is create your Mac Caching services using the ClearPass templates "Guest Mac Authentication"

     

    In the controller make sure you have the following :

    - Cleapass as you mac authentication server source

    - Add a Mac Auth L2 profile

    - Enable Accounting in the aaa profile

    - And ClearPass as your RFC 3576

     



  • 3.  RE: Mac Cache

    Posted Feb 04, 2015 08:33 PM

    victor, how do I do this with Instant APs? 



  • 4.  RE: Mac Cache

    EMPLOYEE
    Posted Feb 04, 2015 08:35 PM

    From the ClearPass side, there is no difference.

     

    To configure MAC-authentication on Instant: 

    http://www.arubanetworks.com/techdocs/Instant_41_Mobile/Advanced/Content/UG_files/Authentication/MAC_Authentication.htm?SearchType=Stem



  • 5.  RE: Mac Cache

    Posted Feb 04, 2015 10:39 PM

    I would assume the MAC Cache service needs to be before the auth service or does it matter?



  • 6.  RE: Mac Cache

    EMPLOYEE
    Posted Feb 04, 2015 10:48 PM
    It just logically makes sense to have it before your web auth service since that's the order it's processed. 


    Thanks, 
    Tim


  • 7.  RE: Mac Cache

    Posted Dec 16, 2014 10:08 AM

     

    Try a few things

    Verify that MAC-Auth is triggered in the Access Tracker. Follow Victors instructions if they don't show there.

     

    Enable Insight under Server Configuration

    On you login-page select "Update Endpoint"

     

    Verify again through access-tracker that mac-auth is triggered.