Security

last person joined: 18 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Random Domain Users Trying to access My CorpWireless

This thread has been viewed 1 times
  • 1.  Random Domain Users Trying to access My CorpWireless

    Posted Jul 23, 2019 05:52 AM

    Hello,

     

    Recently, I have observed that random domains are trying to access my corporate wireless which is being rejected by clearpass.

     

    an example for this is as below:

     

    1424021217514547@wlan.mnc002.mcc424.3gppnetwork.org

    1424021214868847@wlan.mnc002.mcc424.3gppnetwork.org

     

    One thing to mention is that it is coming from only one location in a remote site.



  • 2.  RE: Random Domain Users Trying to access My CorpWireless

    EMPLOYEE
    Posted Jul 23, 2019 06:30 AM


  • 3.  RE: Random Domain Users Trying to access My CorpWireless

    EMPLOYEE
    Posted Jul 24, 2019 03:12 AM

    That are users that try to use Mobile phone SIM authentication on your SSID. You can look up: mcc 424 / mnc 002 is the provide Etisalat in the United Arab Emirates.

     

    Either you, as suggested, configured hotspot 2.0/802.11u on your SSID, or these users manually configured their device with EAP-SIM/EAP-AKA.

     

    Or, you used the same SSID as an SSID elsewhere configured for SIM authentication and the client just tries to authenticate when it recognizes the SSID.

     

    Do you recognize any of these conditions?



  • 4.  RE: Random Domain Users Trying to access My CorpWireless

    Posted Jul 31, 2019 03:40 AM

    Thanks, Joseph and Herman for the reply.

     

    I have checked in the controller if hotspot 2.0 were enabled and it was not, the profile was set to N/A. I would assume that this is not enabled.

     

    Any other ideas? 

     

    Your replies are highly appreciated



  • 5.  RE: Random Domain Users Trying to access My CorpWireless

    EMPLOYEE
    Posted Jul 31, 2019 09:27 AM

    If it is the same clients, it could be a couple misconfigured clients occasionally attempting to attach to your network.