Security

last person joined: yesterday 

Enterprise security using ClearPass Policy Management, ClearPass Security Exchange, IntroSpect, VIA, 360 Security Exchange, Extensions and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Match on MPSK

  • 1.  Match on MPSK

    Posted Apr 08, 2019 03:22 AM

    I'm guessing the answer is NO based on testing so far, but worth asking all the same.

     

    Can you match, using ClearPass role mapping or enforcement policies, on the PSK entered against an MPSK wireless network by the user?



  • 2.  RE: Match on MPSK

    Posted Apr 08, 2019 07:09 AM
    No, that's not how WPA2-Personal works.


  • 3.  RE: Match on MPSK

    Posted Apr 08, 2019 07:26 AM

    If you have MPSK deployed, you might be able to do what you try by working indirectly with attributes in other authorization sources like the endpoint database or the guest device database entry.

     

    As the MPSK is bound to a device, you can assume that the correct MPSK is used for that device. If you are looking to have different roles depending on the PSK entered, that doesn't work like Tim mentioned as there is only one single PSK that will be accepted for that device. What you still can do is return roles depending on the device, or profiling information, and so on.



  • 4.  RE: Match on MPSK

    Posted Apr 09, 2019 08:35 AM

    @

     



  • 5.  RE: Match on MPSK

    Posted Apr 09, 2019 08:46 AM
    Unfortunately that's not how WPA2-Personal works.