Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Can I "blacklist" all mobile devices from connecting to company wifi?

This thread has been viewed 2 times
  • 1.  Can I "blacklist" all mobile devices from connecting to company wifi?

    Posted Sep 09, 2014 04:49 PM

    I have Clearpass as well as mobility controllers with 350 AP's.  Is there a easy way to disable devices from connecting to the wifi?  we have AD policies requiring users to change their password every 90 days.. they forget to change their wifi password on their smart device (BB, Android, iPhone) and their account gets locked out and someone from the service desk needs to unlock.  Clearpass gave us the ability to find the source of the lockout but still cumbersome.  Can I revoke this globally?



  • 2.  RE: Can I "blacklist" all mobile devices from connecting to company wifi?

    EMPLOYEE
    Posted Sep 09, 2014 05:19 PM
    Not really. The device has to connect once in order for it to be profiled and then you can put the user into a deny all all role but at that point, authentication has already happened.

    Why not onboard the devices to alleviate the password issues?


  • 3.  RE: Can I "blacklist" all mobile devices from connecting to company wifi?

    EMPLOYEE
    Posted Sep 09, 2014 11:55 PM

    Also if you are running aruba controllers you can enable the blacklist for failed auths

     

    For example: you can blacklist anyone that failed authentication 4 times so if your AD has a 5 failed auth limit they will not lock up the AD account.

     

    Screen Shot 2014-09-09 at 10.50.54 PM.png



  • 4.  RE: Can I "blacklist" all mobile devices from connecting to company wifi?

    Posted Sep 10, 2014 10:13 AM

    yes, I have aruba controllers... once the client fails auth 4 times.. it will not allow them to connect?  does it blacklist it for good?  because once they fix their password issue, I want them to connect again.



  • 5.  RE: Can I "blacklist" all mobile devices from connecting to company wifi?

    EMPLOYEE
    Posted Sep 10, 2014 10:42 AM
    I believe it is by default 1 hour. One of the controller guys will need to confirm.


  • 6.  RE: Can I "blacklist" all mobile devices from connecting to company wifi?

    Posted Sep 29, 2014 09:34 AM

    I enabled this, however, lockout clients are are still attempting to connect.  is there something else that needs to be enabled?

     

    Capture.JPG



  • 7.  RE: Can I "blacklist" all mobile devices from connecting to company wifi?

    EMPLOYEE
    Posted Sep 29, 2014 09:52 AM

    Do you have station blacklisting enabled in your virtual-ap?



  • 8.  RE: Can I "blacklist" all mobile devices from connecting to company wifi?

    Posted Sep 29, 2014 10:22 AM

    yes



  • 9.  RE: Can I "blacklist" all mobile devices from connecting to company wifi?

    Posted Sep 29, 2014 10:24 AM

    does anything need to be enabled here?Capture.JPG



  • 10.  RE: Can I "blacklist" all mobile devices from connecting to company wifi?

    Posted Oct 12, 2014 06:34 AM

    i don't believe so. is it still not working? have you tested it yourself to see if you get on the blacklist?



  • 11.  RE: Can I "blacklist" all mobile devices from connecting to company wifi?

    Posted Oct 13, 2014 09:41 AM

    Yes, I have this working.. works great..  just enabled it on the controller with a timer.



  • 12.  RE: Can I "blacklist" all mobile devices from connecting to company wifi?

    Posted Sep 10, 2014 09:26 AM

    The problem with onboarding is that they are already company provisioned devices (MDM = Airwatch)..also Blackberry is not supported and I would have to create a separate SSID for mobile devices because we have company laptops connecting already.  I dont want cert based auth for laptops.