Security

 View Only
last person joined: 8 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass MAC authentication and Enhanced Open SSID

This thread has been viewed 20 times
  • 1.  ClearPass MAC authentication and Enhanced Open SSID

    Posted Mar 29, 2021 04:34 PM
    I'm looking into a strange behavior of a client connected to guest ssid configured as Enhanced Open. Client stays connected to hidden ssid like _owetm_MYGUEST_SSID_mac and never transition to MYGUEST_SSID. If I configure MAC service to use EQUALS for SSID, this client can't connect to the network at all as service categorization is failing. I need to use CONTAINS in the service definition.

    I'm wondering if this is because this client maybe does not support Enhanced Open or I have something wrong configured on the controller or ClearPass. Looking into client fingerprint it is Android 10 on mobile phone.

    ------------------------------
    Gorazd Kikelj
    ------------------------------


  • 2.  RE: ClearPass MAC authentication and Enhanced Open SSID

    MVP EXPERT
    Posted Mar 29, 2021 07:17 PM
    When transition mode is enabled, the hidden SSID is the Enhanced Open network. If the client is associating to that ESSID, then it is EO-capable. Your CPPM rule needs to use an ENDS_WITH operator for the ESSID name if you're using transition mode.

    ------------------------------
    Tim C
    ------------------------------



  • 3.  RE: ClearPass MAC authentication and Enhanced Open SSID

    Posted Jun 14, 2023 10:00 PM

    With a central managed AOS10 AP, it seems to also add a random number to the end of the ESSID. So either use Contains, or use a BELONGS_TO list