Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass MPSK Form Options

This thread has been viewed 49 times
  • 1.  ClearPass MPSK Form Options

    Posted Mar 22, 2019 01:18 PM

    I'm playing with the new MPSK feature in 6.8 and have run up against a few inconveniences.

     

    I see under MSPK configuration...

     

    Device Wi-Fi passwords are sent via email receipts and valid SMTP server settings must be provided.

     

    Is there a way to change this so users can set the MPSK when creating the device or view the MPSK in the GUI Receipt? I've added mpsk and mpsk_enable fields to my mac_create and mac_trac_create forms, but that doesn't help any.

     

    I've also added them to Manage Devices, and it shows a PSK has been generated but does not display it. 

    mac_list.jpg

     

    My end goal was to have a Self-Service Portal where guest users could see their own devices and PSKs and easily add new devices or change PSKs.



  • 2.  RE: ClearPass MPSK Form Options

    Posted Mar 22, 2019 01:28 PM

    Is there a way to change this so users can  ....  view the MPSK in the GUI Receipt? 

     


    Figured this part out. Just had to add the MPSK field to the receipt forms.

     

    mac_create_receipt.jpg



  • 3.  RE: ClearPass MPSK Form Options

    MVP EXPERT
    Posted Mar 22, 2019 08:09 PM

    Iam also testing the new WPA2-MPSK feature. Works perfect.

     

    One thing i try to reach is the import/export feature include the WPA2 keys. When use the MPSK field in it it doesnt work in the import/export.

     

    I want to bulk upload mac-adresses with the MPKS key from another wlan environment. So i mean without the use of auto generate new keys.

     

    Also when add the field MPKS it dont shows the passwords, how can i make them visable?

     

    Capture.JPG

     

     



  • 4.  RE: ClearPass MPSK Form Options

    MVP EXPERT
    Posted Mar 24, 2019 05:48 PM
    Anybody?


  • 5.  RE: ClearPass MPSK Form Options
    Best Answer

    Posted Mar 26, 2019 11:35 AM

    I've found a way to import MPSK.

    You need to add two fields to your spreadsheet: mpsk and mpsk_enable

    mpsk spreadsheet.jpg

     

    You'll see that they both come in as auto-detected fields for "Wi-Fi Password"

     

    mpsk import.jpg

     

    I can make the PSK show in the receipts; however, I still cannot make them visible in the "Manage Device" list, nor can I manually set them within Guest.  

     



  • 6.  RE: ClearPass MPSK Form Options

    MVP GURU
    Posted Mar 26, 2019 11:38 AM

    @mkk wrote:
    Anybody?

    May be i will be also with API...



  • 7.  RE: ClearPass MPSK Form Options

    EMPLOYEE
    Posted Mar 26, 2019 11:40 AM
    Would you show a user’s AD password in a list like that? This is a network credential and is not visible in bulk form.


  • 8.  RE: ClearPass MPSK Form Options

    Posted Mar 26, 2019 11:56 AM

    Understood.

    But I would expect a user to be able to define their own PSK (vs. having to randomly generate or import a spreadsheet), and I've yet to find a way to do this.



  • 9.  RE: ClearPass MPSK Form Options

    EMPLOYEE
    Posted Mar 26, 2019 11:57 AM
    MPSKs are only generated automatically using the generator functions.


  • 10.  RE: ClearPass MPSK Form Options

    Posted Apr 12, 2019 12:49 AM

    Thank you for this post. Its been helpful , I added a few more fields here is something I put together. Hope its useful.

     

    Screen Shot 2019-04-11 at 9.45.39 PM.png

     



  • 11.  RE: ClearPass MPSK Form Options

    Posted Sep 02, 2019 06:09 AM

    Hi,

    I've managed to import devices and their individual PSKs and that works on the Wi-Fi. But I'm having trouble visualizing the PSK per device using the print template "Device Registration". The Wi-Fi password is not shown when the device was created with CSV import. However, when I create the device through the GUI (button "Create"), the print template shows the Wi-Fi password just fine.

    Anyone else encountered this?

    Regards,

    Dante



  • 12.  RE: ClearPass MPSK Form Options

    MVP EXPERT
    Posted Sep 02, 2019 06:16 AM

    --- EDIT --- Very good answer by jfox below --- EDIT ---

     

    Capture.JPG



  • 13.  RE: ClearPass MPSK Form Options

    Posted Sep 02, 2019 06:27 AM

    Hi Marcel,

    Thanks for that info, it could have taken me a while to realize that you can only print/email the password once, you saved me some time!

    Regards,

    Dante



  • 14.  RE: ClearPass MPSK Form Options

    Posted Sep 02, 2019 08:08 AM

    Hi guys,

    I probably should have updated this thread earlier.

     

    You CAN actually view passwords once they are created, and export them as well. You need to enable "Password Display" under Guest Manager. Then add the MPSK field to your mac_list and mac_export fields. This will allow a super admin to view and export device lists with Wi-Fi passwords.



  • 15.  RE: ClearPass MPSK Form Options

    Posted Sep 02, 2019 08:22 AM

    Late or not, it's good news! The customer IT administrators will be pleased to hear their all-access-pass isn't being limited ;-).



  • 16.  RE: ClearPass MPSK Form Options

    MVP EXPERT
    Posted Sep 02, 2019 08:23 AM

    Very good jfox! Was looking for this a long time :). Just tested in CP 6.8.1 and works great.