As @ahollifield describes in his linked blog post you can utilize the MAC Vendor information, also without DHCP profiling. He utilize the additional information from the profiling to make sure the device is aslo the expected type. Not just any device from HP but also checking it's a printer.
In the described setup any device from a given vendor is accepted at first, get profiled, and forced to do a new authentication after a dynamic authorization. In the second authentication ClearPass has the profiling information and only the allowed device type from the given vendor is accepted.
So if you have a vendor and only one device type from this vendor you may not need to do the profiling. Could be Crestron for video conference system or Humbly for booking panels etc.
------------------------------
Best Regards
Jonas Hammarbäck
MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
Aranya AB
If you find my answer useful, consider giving kudos and/or mark as solution
------------------------------
Original Message:
Sent: Oct 03, 2024 02:50 AM
From: Sebjoh
Subject: Clearpass MPSK device groups and dynamic vlan?
I did try to set clearpass as authsource without finishing the mpsk setup and just to see what info clearpass would get from the devices, i already can see alot info about the device, like vendour oui etc. is that enough?
Original Message:
Sent: Oct 02, 2024 08:31 AM
From: ahollifield
Subject: Clearpass MPSK device groups and dynamic vlan?
Yes, you need someway to get that profiling data into ClearPass. Doesn't have to be DHCP but that's typically the most valuable probe. You of course can also just use static MAC assignment in the guest repository for example but that's less scalable and less secure than using profiling.
Original Message:
Sent: 10/2/2024 8:23:00 AM
From: Sebjoh
Subject: RE: Clearpass MPSK device groups and dynamic vlan?
This looks great, currently not using a MC, but IAP, do i need to also send dhcp requests?
Original Message:
Sent: Sep 30, 2024 08:11 AM
From: ahollifield
Subject: Clearpass MPSK device groups and dynamic vlan?
https://www.adamhollifield.com/2022/09/clearpass-mpsk-per-device-type-with.html
Original Message:
Sent: Sep 30, 2024 02:30 AM
From: Sebjoh
Subject: Clearpass MPSK device groups and dynamic vlan?
Hi
I want to start using mpsk for some 3 party devices that can only use psk as auth method, and i also want to give these devices their own vlan back.
I looked into MSPK and it seems to be the way to do this, but it seems that i have to register all the devices in Clearpass? Is there an way to do mac prefix instead of register 600 devices?
So if device has mac prefix 03:2d:12: and uses psk ***** then clearpass should auth the device and send the correct vlan for that device group back to the ap.