Security

last person joined: 15 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM-MAC Authentication configuration with time source

This thread has been viewed 1 times
  • 1.  CPPM-MAC Authentication configuration with time source

    Posted Nov 12, 2015 09:43 PM

    Hi Guys, 

    I have created a mac address authentiction service that will match against a static host list defined on my clearpass. However i am thinking of implementing a time source whereby the user will be barred after 3 days. How can that be done ? Would be good to give specific details as i am still pretty new with clearpass.



  • 2.  RE: CPPM-MAC Authentication configuration with time source
    Best Answer

    EMPLOYEE
    Posted Nov 12, 2015 10:13 PM

    Static host lists would not be the route to take here. I would go with device registration (MACTrac) in ClearPass Guest. 

     

    This is a fairly advanced concept if you don't have much CP experience. You may want to work with your ClearPass partner. Here's a link if you want to try it yourself.  

     

    http://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/How-To-Advanced-MACTrac-designs-in-ClearPass-November-MHC/td-p/217291

     



  • 3.  RE: CPPM-MAC Authentication configuration with time source

    Posted Nov 12, 2015 11:01 PM

    Hi Cappalli, So for static host list, i am unable to set a client expiry date/time ? Would you recommend using end point instead since i can set an expiry date there.



  • 4.  RE: CPPM-MAC Authentication configuration with time source

    EMPLOYEE
    Posted Nov 12, 2015 11:04 PM

    I recommend using device registration in CPG...



  • 5.  RE: CPPM-MAC Authentication configuration with time source