Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Aruba clear pass to prevent simultaneous Wi-Fi and Wired Access

This thread has been viewed 39 times
  • 1.  Aruba clear pass to prevent simultaneous Wi-Fi and Wired Access

    Posted Nov 15, 2021 11:25 AM
    Hello,

    We have the following security requirement in my company's internal corporate network: We have several Wi-Fi access points installed inside my company buildings which provide direct internet access for guests. However, these Wi-Fi access points are used also from employees who are connected with their corporate laptop to the wired internal network and also connect via wi-fi for getting unrestricted Internet access. This is not allowed by the security policy but a lot of employees do it all the time in order to circumvent the restrictions of the internal network and get unrestricted Internet access from the Wi-Fi.

    I was wondering if Aruba Clear pass solution can help us to prevent employees from connecting to the guest Wi-Fi access points while they are connected to the internal network. Can we use Aruba clear pass in any way for providing such restriction? Maybe a NAC agent can check whether wireless is enabled on the laptop and if it's enabled it won't allow wired access to the internal network. Is this possible?



    ------------------------------
    Rosario Cobolli
    ------------------------------


  • 2.  RE: Aruba clear pass to prevent simultaneous Wi-Fi and Wired Access

    MVP GURU
    Posted Nov 15, 2021 08:21 PM
    Have you checked the settings on the NIC drivers? Usually there is a setting you can turn on that will disable the wired port of you are connected to wifi. This can be controlled via GPO on windows domain machines, and other MDM solutions.

    ------------------------------
    Dustin Burns
    Lead Mobility Engineer @WEI

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2021
    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 3.  RE: Aruba clear pass to prevent simultaneous Wi-Fi and Wired Access

    Posted Nov 16, 2021 04:05 AM
    Hi Dustin,
    thanks for your reply.
    But regardless of GPO or MDM, can Clearpass block wireless when connected via cable?

    ------------------------------
    Rosario Cobolli
    ------------------------------



  • 4.  RE: Aruba clear pass to prevent simultaneous Wi-Fi and Wired Access

    EMPLOYEE
    Posted Nov 16, 2021 04:25 AM
    You can do that with OnGuard:

    From just the network is it hard to impossible to check if a wireless and wired connection are belonging to the same client, as these typically have the same MAC addresses.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: Aruba clear pass to prevent simultaneous Wi-Fi and Wired Access

    Posted Aug 22, 2023 09:18 AM

    Hi Herman.

    I tried to configure it on the page you post here. 
    It only sends me a message to OnGuard that I should close one of them.
    It doesn't disconnect the WiFi automatically.
    Do you think it is possible? Disconnecting the WiFi automatically when Wired is connected ?



    ------------------------------
    Best regards,
    Alon Haber
    ------------------------------



  • 6.  RE: Aruba clear pass to prevent simultaneous Wi-Fi and Wired Access

    EMPLOYEE
    Posted Aug 22, 2023 11:39 AM

    If you have configured OnGuard like this:

    I would expect that Onguard actively disconnects one of your networks. If it doesn't, please open a support case. for that.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 7.  RE: Aruba clear pass to prevent simultaneous Wi-Fi and Wired Access

    MVP
    Posted Nov 16, 2021 12:51 PM
    You can check some of the following options under this link:

    http://woshub.com/disable-wi-fi-when-ethernet-cable-connected/

    ------------------------------
    Shpat
    ------------------------------