Security

 View Only
last person joined: 2 days ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

aruba quick connect static mac configuration

This thread has been viewed 21 times
  • 1.  aruba quick connect static mac configuration

    Posted 9 hours ago

    Hi,

    I configured a new Onboarding service. All it's working fine, except for a detail about mac of devices.

    I need to pass different vlan to android device, they are same category and also the user is the same, so I'm trying to use SHL for discriminate the device and the vlan.

    It is working, but devices are configured to use dynamic mac addresses.

    I tried to configure static, but it seems that it is not possible on ssid managed by quick connect.

    Does anyone know how to set static mac address with quick connect?

    Thanks



    ------------------------------
    carabina5
    ------------------------------


  • 2.  RE: aruba quick connect static mac configuration

    Posted 8 hours ago

    What is SHL?  What is the use-case for OnBoard?  Is there an MDM?  Can you integrate ClearPass with that instead?




  • 3.  RE: aruba quick connect static mac configuration

    Posted 8 hours ago

    Hi, 

    Static host list (list of mac addresses in Clearpass).

    The customer doesn't have an MDM, there are about 20 tablets...
    Thanks



    ------------------------------
    carabina5
    ------------------------------



  • 4.  RE: aruba quick connect static mac configuration

    Posted 8 hours ago

    Static host lists are a legacy feature and should no longer be used.  If there is no MDM how is the customer ensuring these tablets are up to date, not rooted, secure, etc?  What is the use-case for allowing these unmanaged tablets onto the protected corporate network.  




  • 5.  RE: aruba quick connect static mac configuration

    Posted 8 hours ago

    You are misunderstenting,

    the feature used is OnBoarding, auth with certificate.
    The use of SHL is only for differntiate two categories of tablet (unfortunatelly same model and same user, different behaviour).
    The tablet are join a blocked vlan, with only a service enabled.
    The point isn't the security, I don't want to discuss with che customer, he don't have mdm and don't wont to buy one.
    He just want use onboarding to process tablet auth, and this is done.

    The problem is to assign 2 different vlan, I'm using SHL to enforce the vlan, not for auth, I know I can use other features, but this is the rapid way for me to configure it. 

    So, the problem is to set static mac in the ssid managed by "quick access". I can change settings in all other SSID, but not this one.

    Thanks



    ------------------------------
    carabina5
    ------------------------------