Wireless Access

last person joined: 17 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

When a device connects the first time and gets fingerprinted and mac-cached, will it be ...

This thread has been viewed 1 times
  • 1.  When a device connects the first time and gets fingerprinted and mac-cached, will it be ...

    Posted Sep 12, 2016 02:20 PM

    When a device connects the first time and it gets fingerprinted and mac-cached on clearpass, will it be fingerprinted again the next time it connects?

     

    We want our game console clients to bypass captive portal and self registration but we are concerned on mac-spoofing. We are afraid that if a client connects is game console, turns it off, then spoof the mac using a laptop --- and since it is mac-cached initially, will clearpass be fooled?

     

    Will clearpass fingerprint ever time a device connects or it will not fingerprint a device that is already mac-cached.

     

    Thanky ou.



  • 2.  RE: When a device connects the first time and gets fingerprinted and mac-cached, will it be ...

    EMPLOYEE
    Posted Sep 12, 2016 02:22 PM
    If the device sends a DHCP discover, yes. If the category profile changes,
    the conflict attribute will be triggered. You can write policy that denies
    devices with the conflict attribute.



    Are you using the device registration portal (guest device repository)?


  • 3.  RE: When a device connects the first time and gets fingerprinted and mac-cached, will it be ...

    Posted Sep 12, 2016 02:42 PM

    We haven't implemented anything yet except for Guest users going through a captive portal to connect their phones, tablet, laptop etc. This is using [Guest User Repository] if I am not mistaken.

     

    We are trying to accomodate video game consoles since most of these have no web browser to go through the captive porta. We are thinking that these game console will skip the captive portal instead and connect automatically (using the same SSID).

     

    So we expect that clearpass will fingerprint it and let it connect but it is just that we are concerned about mac-spoofing. We want to make sure these are real video game consoles.



  • 4.  RE: When a device connects the first time and gets fingerprinted and mac-cached, will it be ...

    EMPLOYEE
    Posted Sep 12, 2016 02:44 PM
    Do you want users to register their gaming and media devices so you have a
    record of them or just let them on?


  • 5.  RE: When a device connects the first time and gets fingerprinted and mac-cached, will it be ...

    Posted Sep 12, 2016 02:54 PM

    Yes, we initially want that clients to register their own gaming console but it seems to be more complicated than we expected (unless there's an easy way). If possible, we want to be able to identify a device and points it to a registered client . However, the leadership want clients to be self serving as much as possible and not to involve another staff or receptionist just to register clients gaming consoles.

     

    Anyway right now, we are looking for the best cleapass+gaming console setup that suits our needs. We are open to suggestions.

     

    Thank you.



  • 6.  RE: When a device connects the first time and gets fingerprinted and mac-cached, will it be ...

    EMPLOYEE
    Posted Sep 12, 2016 03:04 PM

    I’d recommend using the device registration portal to allow users to register their own device. It’s designed for headless devices like game consoles, printers, media players, etc.

     

    The forms can be completely customized to hide or add whichever fields you want. By default, it will automatically register the device to the user who logs into the portal.

     

    student-dev-reg-sample.PNG



  • 7.  RE: When a device connects the first time and gets fingerprinted and mac-cached, will it be ...

    Posted Sep 12, 2016 04:32 PM

    Isn't it that this method is to turn each and every student an operator themselves with just the 'registerd a device' option?

     

    I think in order to do this, we have to connect LDAP to clearpass since clearpass itself cannot use our RADIUS server.

     

    If not please direct me to where I can read more about this.



  • 8.  RE: When a device connects the first time and gets fingerprinted and mac-cached, will it be ...

    Posted Sep 26, 2016 12:47 PM

    Hi Tim,

     

    After getting a device registered here, how often will still get fingerprinted? 

    uqa63A2[1].png