Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Self-service guest question

This thread has been viewed 0 times
  • 1.  Self-service guest question

    Posted Aug 01, 2013 06:00 PM

    Hi,

     

    We are looking to implement two networks using Clearpass

     

    1.  Network for guests, which they access using the Self-Service capabilties of Clearpass

    2.  Network for employees, who will on-board their device and connect via EAP-TLS.

     

     

    Question is, is there a way to stop my corporate users accessing the self-service guest network ?



  • 2.  RE: Self-service guest question

    EMPLOYEE
    Posted Aug 01, 2013 06:05 PM
    You can but you will either have register the device on the corporate ssid first or use a static host list to check against to see if its a known device.


  • 3.  RE: Self-service guest question

    EMPLOYEE
    Posted Aug 01, 2013 06:05 PM

    You could try a role map that checks the Onboard status and returns the Deny role if the device is managed:

     

    onboard-yes.PNG



  • 4.  RE: Self-service guest question

    Posted Aug 01, 2013 06:13 PM

    Ok, so once the device is enrolled, I can have that database checked each time someone tries to access the Self-Service guest network, and if that device has been enrolled, they won't be allowed to connect ?

     

     

    If the above is true, can we return them a web-page to tell them to connect to the corporate SSID ?



  • 5.  RE: Self-service guest question

    EMPLOYEE
    Posted Aug 01, 2013 06:15 PM
    Yes, but instead of a deny, create an enforcement profile that returns a
    captive portal role to the controller.



    Sent from my BlackBerry Z10


  • 6.  RE: Self-service guest question

    Posted Aug 01, 2013 06:33 PM

    So by returning that role, would the new page automatically appear on the users device ?



  • 7.  RE: Self-service guest question

    EMPLOYEE
    Posted Aug 01, 2013 06:36 PM
    The enforcement policy would trigger a change of authorization that would
    boot the and bring them into the new role. When the user tries to access a
    website, they would be redirected to a captive portal.

    We do this with students who violate DMCA or AUP.

    Sent from my BlackBerry Z10