Security

last person joined: 11 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

iPAD and iPHONES, how to see the difference?

This thread has been viewed 3 times
  • 1.  iPAD and iPHONES, how to see the difference?

    Posted Feb 17, 2012 04:23 AM

    I have a costumer that uses iPAD’s in production. They want to allow iPAD’s but disallow iPHONES (and all other smart devices) to the network.  They do not want to use MAC-authentication.  I have looked into BYOD and it looks as iPhones and iPads are sending the same DHCP fingerprint. But the controller sees the difference (client à device types). Do anyone know how to use User Rules for this?  



  • 2.  RE: iPAD and iPHONES, how to see the difference?

    EMPLOYEE
    Posted Feb 17, 2012 05:55 AM

    @Tom.christensen@nordialog.no wrote:

    I have a costumer that uses iPAD’s in production. They want to allow iPAD’s but disallow iPHONES (and all other smart devices) to the network.  They do not want to use MAC-authentication.  I have looked into BYOD and it looks as iPhones and iPads are sending the same DHCP fingerprint. But the controller sees the difference (client à device types). Do anyone know how to use User Rules for this?  


    You are correct; the DHCP signature for an iPad and iPhone are the same.  You can only use the DHCP fingerprint for a user derivation rule.  The controller sees the difference in devices by inspecting the browser string, but we cannot create a user derivation rule based on a browser string.  Browser strings are unreliable and can be faked, anyway, so that would not  be a reliable method to disallow access.

     

    What are the iPads using for access to the network, currently?



  • 3.  RE: iPAD and iPHONES, how to see the difference?

    Posted Feb 17, 2012 05:58 AM

    The iPADs are using the WLAN with 802.1x authentication.



  • 4.  RE: iPAD and iPHONES, how to see the difference?

    EMPLOYEE
    Posted Feb 17, 2012 06:03 AM

    @Tom.christensen@nordialog.no wrote:

    The iPADs are using the WLAN with 802.1x authentication.


    Well, you have a two-fold issue:  Any handheld device can get on using 802.1x.

     

    You might want to create an WPA2-PSK SSID specifically for iPads and other non-domain devices that you want on your network.  For your 802.1x SSID you might want to turn on "Enforce Machine Authentication" in the 802.1x profile to ensure that only domain devices get on that network.  Please check out the thread here:  http://community.arubanetworks.com/t5/Security-WIDS-WIPS-and-Aruba-ECS/Machine-amp-User-Authentication-iPhones-getting-online/m-p/1638/highlight/true#M18