Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

QuickConnect Client can be Transferred between workstations with Authentication Information

This thread has been viewed 0 times
  • 1.  QuickConnect Client can be Transferred between workstations with Authentication Information

    Posted Jan 21, 2015 02:44 PM

    QuickConnect Client can be downloaded to a client machine after successful Web Auth, but if a client copies this one file, they can run it on any workstation and it provides them with full internal access on any machine.  It seems like the whole TLS Cert and/or AAA info is being saved and can be run from anywhere.

     

    And suggestions on how to prevent this from occurring?



  • 2.  RE: QuickConnect Client can be Transferred between workstations with Authentication Information

    Posted Jan 26, 2015 12:24 AM
    Does anyone have any ideas how to resolve this issue?


  • 3.  RE: QuickConnect Client can be Transferred between workstations with Authentication Information

    Posted Jan 26, 2015 04:41 AM
    Can you please share your enforcement policy ?



  • 4.  RE: QuickConnect Client can be Transferred between workstations with Authentication Information

    EMPLOYEE
    Posted Jan 26, 2015 05:21 AM

    Mslan,

     

    What OS is this?  Like Vfabien is alluding to, the mac address of the client could be installed into the certificate and that can be checked against the calling-station-id of the host machine during EAP-TLS authentication to stop this.

     



  • 5.  RE: QuickConnect Client can be Transferred between workstations with Authentication Information

    Posted Jan 26, 2015 12:01 PM

    I have attached screen shots of the three Services regarding OnBoard.  The Provisioning shows the Auth and Enforcement Policy/Profile.  The Pre-Auth and Auth show the Authentication, and both have an "accept" as enforcement profiles.

     

    And the OS this is happening on is Windows, both 7 and 8.



  • 6.  RE: QuickConnect Client can be Transferred between workstations with Authentication Information

    Posted Jan 26, 2015 12:23 PM


  • 7.  RE: QuickConnect Client can be Transferred between workstations with Authentication Information

    Posted Jan 26, 2015 01:40 PM

    Where can I set the "calling-station-id" attribute to be recorded and pushed down with the cert, then checked against upon TLS Authentication?



  • 8.  RE: QuickConnect Client can be Transferred between workstations with Authentication Information

    EMPLOYEE
    Posted Jan 26, 2015 02:11 PM

    It should be done automatically.  Look in the Access Tracker for a Windows onboarded device that authenticates via EAP-TLS and see if you see mdpsmacaddress as a radius attribute.

     



  • 9.  RE: QuickConnect Client can be Transferred between workstations with Authentication Information

    Posted Jan 26, 2015 02:39 PM

     

    Radius:IETF:Calling-Station-Id0024d7xxxxxx
    Radius:IETF:Calling-Station-Id0024d7xxxxxx

     

    I do see the attribute in the Access Tracker, as shown above.  But how can I restrict the QuickConnect Client from being run on another machine?  

     

    What would be the proper "Operator" to set the "RADIUS: IETF:" and "Calling-station-ID".  Exists? or "Belongs to..."?



  • 10.  RE: QuickConnect Client can be Transferred between workstations with Authentication Information

    EMPLOYEE
    Posted Jan 26, 2015 03:00 PM

    Mslan,

     

    Let me make sure we are talking about the same thing.  I just onboarded a Windows Computer and When I look at the device certificate in Onboard, this is what I see.  Below is the wired and wireless mac addresses.  Let me know if you see that in your certificate:

     

     

    mac1.png

     

    When I authenticate, this is what I see in the Access Tracker under "Computed Attributes".  Please let me know if you see that, as well.

     

    cert2.png



  • 11.  RE: QuickConnect Client can be Transferred between workstations with Authentication Information

    Posted Jan 26, 2015 03:38 PM

    Yes, I am seeing the device's MAC Address in both the Access Tracker and Guest Manager, as shown below.  

     

    But I can still download and install it from the first PC, then I can copy it over to any other PC, run the QuickConnect Client and it installs everything, without prompting for credentials, or stating that the calling-station-id or mdns-mac-address already exists.

     

     

    CPPM-OnBoard-mdpsMacAddress.png

     

    Any suggestions?

     

    Thanks,



  • 12.  RE: QuickConnect Client can be Transferred between workstations with Authentication Information

    Posted Jan 26, 2015 03:46 PM

    Both Access Tracker shows the Certificate Mac Address, and there is an OnBoard Cert, also showing the two mdnsMacAddresses.

     

    All appears correct, but I was still able to download and run the QuickConnect client on the first PC and all authenticates and OnBoards properly with EAP-TLS.

     

    I then copy the downloaded QuickConnect client to another laptop, run the executable, and it logs me in, generates a new cert and authenticates with EAP-TLS.

     

    Any suggestions?

     

    CPPM-OnBoard-mdpsMacAddress.png

     

    CPPM-Access-Tracker-Cert-MacAddress.png 



  • 13.  RE: QuickConnect Client can be Transferred between workstations with Authentication Information
    Best Answer

    EMPLOYEE
    Posted Jan 27, 2015 07:20 AM

    Mslan,

     

    Please delete that quickconnect.exe file from the computer.  Go to Onboard> Deployment and Provisioning> Provisioning settings and set the Maximum Devices to 1, and then try to re-onboard that device:

     

    onboard.png