Security

last person joined: 19 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

User Roles and WPA2-PSK

This thread has been viewed 8 times
  • 1.  User Roles and WPA2-PSK

    Posted Nov 15, 2014 07:44 PM

    How is user role determined from WPA2-PSK method of authentication?

     

     



  • 2.  RE: User Roles and WPA2-PSK

    EMPLOYEE
    Posted Nov 15, 2014 07:46 PM
    By default, the user-role is what is defined as the initial role in the AAA profile. You can also use user derivation rules or RADIUS with MAC authentication for dynamic role assignment.


  • 3.  RE: User Roles and WPA2-PSK

    Posted Nov 15, 2014 07:49 PM

    Ahhhh....so you can't define a post-authentication role for that method? 



  • 4.  RE: User Roles and WPA2-PSK

    EMPLOYEE
    Posted Nov 15, 2014 08:03 PM
    No, because no authentication has occurred. You would need to add MAC authentication.


  • 5.  RE: User Roles and WPA2-PSK

    Posted Jul 14, 2017 12:16 PM

    Hi Tim,

     

    You said:

     

    No, because no authentication has occurred.

     

    With WPA2-PSK you must enter the preshared key when you connecto to the network and the controller checks that preshared key, it is correct you can access the network, otherwise you can't. For me this is a kind of authentication, do you mean an authentication based on user?

     

    Regards,

    Julián



  • 6.  RE: User Roles and WPA2-PSK

    Posted Jul 19, 2017 10:37 AM

    I think Tim means that no authentication has occurred against Clearpass.  I asked a similar question a while back here: https://community.arubanetworks.com/t5/Security/PSK-SSID-Endpoint-Repository-for-role-assignment/m-p/297425#M31804

     

    Once MAC auth was configured, I was able to leverage additional authorization steps against Clearpass to determine which role the client should be getting.



  • 7.  RE: User Roles and WPA2-PSK

    Posted Mar 21, 2017 03:23 AM

    Hi Tim.

     

    Does this mean you can do PSK auth, have a device get the AAA initial role, then have that role subsequently changed by a user derivation rule?   It says in the docs that user derivation rules apply pre-authentication, I thought that meant it would only apply to open SSID users.  Please confirm.  thank you.

     

    Neal



  • 8.  RE: User Roles and WPA2-PSK

    EMPLOYEE
    Posted Mar 21, 2017 11:20 AM

    Yes, the deriviation rule would be evaluated.