Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass,AppleTv and Mac-Caching -Issue

This thread has been viewed 0 times
  • 1.  ClearPass,AppleTv and Mac-Caching -Issue

    Posted Jul 07, 2014 07:13 PM

    Hello's, and excuse the lengthy email :smileyfrustrated:

    I have an interesting scenario.

     

    I have a controller SSID whose login page is ClearPass. Users authenticate to this splash page using their AD credentials. I also have Mac-Caching enabled which allows users sessions who have authenticated once to stay "alive" for the duration of the Mac-Caching settings.

     

    We are also using ClearPass Guest and we allow our users to register their AppleTv devices and share them to their colleagues using their colleages AD credentials. Everything works initially; The controller can share the Apple tv to the correct usrs by using their AD user names which were provided when the device was registerd in ClearPass.  The issue it seems arises when Mac-caching kicks in.

     

    From what I've been able to gather, when an AppleTv is first shared it is shared to the AD cred's and this info is published to the controller and managed by Airgroup. Once Mac Caching kicks in, the user is no longer known by the controller by his AD user name but by a mac-address. In Clearpass, the Atv is shared to AD user accounts, and on the controller AirGroup knows the ATv is shared to the AD user name and therefore once Mac-Caching kicks in the users lose access to the AppleTv. Has anyone else run into this? Any ideas?

    Thanks much for your time,

    Sky



  • 2.  RE: ClearPass,AppleTv and Mac-Caching -Issue
    Best Answer

    EMPLOYEE
    Posted Jul 07, 2014 08:40 PM

    You need to return the username to the controller in your MAC-auth service.

     

    radius-sponsor-name.PNG



  • 3.  RE: ClearPass,AppleTv and Mac-Caching -Issue

    EMPLOYEE
    Posted Jul 07, 2014 11:44 PM
      |   view attached

    I thought I posted these a while back but I will post them again. All you need to do is import these into your enforcement profiles.  :)

     

    Password: aruba123

     

    Screen Shot 2014-07-07 at 10.39.47 PM.png

    Attachment(s)



  • 4.  RE: ClearPass,AppleTv and Mac-Caching -Issue

    Posted Jul 08, 2014 03:19 PM

    Troy,

    Thanks for the uploads. They augmented the solution well.

    thanks again,

    Sky



  • 5.  RE: ClearPass,AppleTv and Mac-Caching -Issue

    Posted Jul 08, 2014 03:18 PM

    Tim,

    Thanks much for your quick response.

    This worked.

    thanks again,

    Sky