Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

One device for one dot1x authenticated user

This thread has been viewed 0 times
  • 1.  One device for one dot1x authenticated user

    Posted Jun 03, 2016 11:00 AM

    Hi All,

    Requirement: User first time connects to the network, and gets registered with the same device. Now the user should not be able to authenticate himself from other device until someone clear the registered device of the respective user from CPPM manually.

    Can it be done ?



  • 2.  RE: One device for one dot1x authenticated user

    EMPLOYEE
    Posted Jun 03, 2016 11:03 AM
    You can you a session device limit with Insight to limit each user to one device. 


  • 3.  RE: One device for one dot1x authenticated user



  • 4.  RE: One device for one dot1x authenticated user

    Posted Jun 08, 2016 02:11 AM

    ok,

    I am going to use the insight method,

    So far I got this,

    1st time user1 is loggin in from device1 > authenticated.

    2nd time user1 is logging in form device2 > denied. Which is fine.

    But if the user2 is logging in from device1 (user1 already logged in from device1) > authenticated (I want this to be denied).

    This is what I dont want, once a user1 log in from a device1 it would get register for that particular user. Other user (user2) should not be able to login from that device (device1).

     

    Also how many days insight repository will cache the auth session details.

     



  • 5.  RE: One device for one dot1x authenticated user

    Posted Jun 08, 2016 05:19 AM

    Ok,

    this   http://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/Limit-User-Authentication-to-1-Device-for-a-period-of-time/ta-p/234016   can block the user to log in from other device in a 12 hours period.

    But different users can still log in from same device. How to block them ?



  • 6.  RE: One device for one dot1x authenticated user

    MVP
    Posted Jun 08, 2016 05:52 AM

    Not sure if it is the best possible way to do this, but you could simply save the username with the endpoint on the first authentication, then simply compare new usernames to what you saved with that endpoint.