With MPSK WLAN, the preshared key is not stored locally in the controller, but is sent as a radius VSA from the ClearPass to the controller. Your enforcement profile only needs to send back the correct value, so both are possible.
You can use a dedicated key for each device. In this case, you save it in the guest device and reference it in the enforcement profile with "Radius:Aruba Aruba-MPSK-Passphrase = %{Authorization:[Guest Device Repository]:Device MPSK}
".
Alternatively, use one key per device type/device guest role. In this case, you set the key in the enforcement profile "Radius:Aruba Aruba-MPSK-Passphrase = aruba123
". The ClearPass GUI does not allow you to select a value yourself, one is generated automatically. If you want to use your own key, export the enforcement profile to XML, set your own key and import the profile.
------------------------------
Regards,
Waldemar
ACCX # 1377, ACEP, ACX - Network Security
If you find my answer useful, consider giving kudos and/or mark as solution
------------------------------
Original Message:
Sent: Jun 01, 2024 09:31 PM
From: cdelarosa
Subject: MPSK Question
I have a fast question regarding this.
Does it allow just one device per password or many device can log in with the same password
What I want to know if its a one to one password or I can log in with on password for example all my cameras log In with this password and all my printers log in with this one something like that.
Thanks