Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

AD+SHL source base authentication

This thread has been viewed 3 times
  • 1.  AD+SHL source base authentication

    Posted Jul 22, 2014 09:53 PM

    Hi,

     

    1) I have configured EMPL ssid for vlan 10 & vlan 20 & that is working fine.

     

    vlan 10 enforcement(for internal lan access) = AD + machine authentication

    vlan 20 enforcement(for full internet access) = AD + Endpoint (make mac id as Known)

     

    2) Now i am configuring ADMIN ssid for 50  non domain devices.

     

    vlan 30 enforcement(for limited internet access) = AD + mac auth (Static host list)

    vlan 40 enforcement (for specific internet access) = AD + mac auth (Static host list)

     

    I have creaded 50 static host entry with respective name & discription.

    I have created 5 authentication source(static host group) & add the respective static host in there group.

    I have created 5 enforcement policies for 5 static host group.

     

     

    I want to assign 5 static host group to 5 enforcement policies.

    Can some one tell me that, what should i configure in service. i.e. authentication source, authorization, role, enforcement & rule.

     

    Thanks in advance....

     

     

     



  • 2.  RE: AD+SHL source base authentication
    Best Answer

    Posted Jul 23, 2014 01:50 AM
    In the enforcement policy use the Connection > Client MAC address >Belongs to group and the select SHL group


  • 3.  RE: AD+SHL source base authentication

    Posted Jul 23, 2014 02:13 AM

    Thanks for reply...

     

    For time being i hv assigned SHL but as i said i hv added SHL per mac id & there is only single mac id entry.

    I hv created 5 authentication source entry & i hv added SHL in respective source.

    Now i want to to authentication through authentication source group.