Security

last person joined: 2 days ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM + 802.1x working great but config question ...

This thread has been viewed 0 times
  • 1.  CPPM + 802.1x working great but config question ...

    Posted Sep 02, 2014 02:56 PM

    So I have our new cppm set up and running. I am running a beta in two different buildings and so far so good. 802.1x/PEAP with cert working and whatnot.

     

    A new scenerio has arisen in that our helpdesk would like to put two desktops on the secure wireless in an area that feasably cannot have any drops installed. My question is this; how do I set it up so just the machines authenticate onto the 802.1x wireless (which drops right into a domain VLAN like our wired machines do) and would then let whomever authenticate with their AD credentials? (meaning that the help desk people will be rotating through this position)

     

    Make sense?

     

    Thanks again gang :-)



  • 2.  RE: CPPM + 802.1x working great but config question ...

    EMPLOYEE
    Posted Sep 02, 2014 02:58 PM
    Are these AD-joined Windows machines?


  • 3.  RE: CPPM + 802.1x working great but config question ...

    Posted Sep 02, 2014 03:12 PM

    @cappalli wrote:
    Are these AD-joined Windows machines?

    Yep :-)



  • 4.  RE: CPPM + 802.1x working great but config question ...

    EMPLOYEE
    Posted Sep 02, 2014 03:23 PM

    OK, so you'll want to configure these machines using group policy.

     

    You'll want the computers to either 1) be in their own OU or 2) Be in a group

     

    You can then use a combination of that data plus the built-in role of [Machine Authenticated] to dump the computer into a machine auth role. You'll want to make sure your enforcement policy allows cached roles and posture.

     

    The screenshots below should get you started:

     

     zCFCC-2.JPG

     

     

     

    zCFCC-1.JPG

     

     



  • 5.  RE: CPPM + 802.1x working great but config question ...

    Posted Sep 02, 2014 03:29 PM

    Much appreciated Tim, I'll start digging into this!



  • 6.  RE: CPPM + 802.1x working great but config question ...

    EMPLOYEE
    Posted Sep 02, 2014 03:33 PM

    For the group policy piece:

     

    gpo-wireless-location.png

     

     

     

    gpo-wireless-tab1.png

     

     

    gpo-wireless-tab2.png

     

    gpo-wireless-tab3.png

     

    gpo-wireless-tab4.png