Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Guest - Internet access allowed before validation

This thread has been viewed 0 times
  • 1.  Clearpass Guest - Internet access allowed before validation

    Posted Dec 17, 2013 07:37 AM

    Hello,

     

    We have Clearpass Guest 6.1.2.25166, part of  ClearPass Policy Manager 6.1.2.53442 to allow our guest to have internet access. We use aruba 3600 controllers (with the 6.2.1.4 firmware i recently updated).

     

    Clearpass Guest is configured with self registration and sms. Our guest suppose to regisger on a webpage, receive a sms and authenticate with username and password, where the username is their e-mail and the password is a password send by sms.

     

    This seem to work fine. 

     

    The only thin is that employees are reporting that their guests already have access before receiving the sms and entering the information in the logon page.

     

    What could be the issue? Could this be an issue between the initial profile and the real guest profile on the aruba controller? Or could this be something else?

     

    I'm not sure where to start.

     

    Any suggestion?

     

    Thank you in advance.

     

    Regards,

    Roland


    #3600


  • 2.  RE: Clearpass Guest - Internet access allowed before validation
    Best Answer

    EMPLOYEE
    Posted Dec 17, 2013 07:42 AM

    I would do a test registration and see if there is a login button on your summary/receipt page. All they have to do is click that and the system will do a background login (CoA to the controller).

     

    guest-reg-login.png



  • 3.  RE: Clearpass Guest - Internet access allowed before validation

    Posted Dec 17, 2013 10:00 AM

    Yes, this was the problem.

     

    On the receipt page the login button was displayed. I had an automaticly redirect configured to the login page from the receipt page with a 5 seconds delay, but the button was displayed during those 5 seconds.

     

    So the beheviour was that someone who was quick enough to click the login button was given directly internet access from the receipt page, while someone who didn't click the button needed to wait for the sms.

     

    I disabled the login button and now this is working as expected, they should not be able anymore to get direct access withouth the password send in the sms. 

     

    Thank you for the quick support.

     

    Regards,

    Roland



  • 4.  RE: Clearpass Guest - Internet access allowed before validation

    Posted Jul 08, 2014 04:18 PM