Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass MAC bypass before 8021.x with IAP

This thread has been viewed 7 times
  • 1.  Clearpass MAC bypass before 8021.x with IAP

    Posted Feb 17, 2019 01:07 PM

    Hello all

    Recently we deployed Clearpass as Radius server. There is some IAPs for wireless. We deployed 802.1x authentication for SSID. It works great. But my question is : Is it possible to deploy Mac-address bypass before 8021.x with the same SSID?

     

    For example, there is an Apple computer which is not in the domain. I want this device to pass authentication without 8021.x if the mac address is in the Static Host List.

     

    Any help would be appreciated,

    Thank you

     



  • 2.  RE: Clearpass MAC bypass before 8021.x with IAP

    EMPLOYEE
    Posted Feb 17, 2019 01:47 PM
    You would use the MAC address as part of authorization to deny the request.


  • 3.  RE: Clearpass MAC bypass before 8021.x with IAP

    Posted Feb 17, 2019 02:58 PM
    Hello Mr Cappalli
    My point is here not to block by mac address. I want some specific device which is in the static host list, to connect without domain username password.


  • 4.  RE: Clearpass MAC bypass before 8021.x with IAP
    Best Answer

    EMPLOYEE
    Posted Feb 17, 2019 04:13 PM
    No, this is not possible. You cannot mix encrypted and unencrypted on the same SSID by standard.


  • 5.  RE: Clearpass MAC bypass before 8021.x with IAP

    Posted Feb 18, 2019 05:43 AM

     thank you for your response.

    If I am not mistaken, it is possible with wired solution. For example, IP telephones can pass authentication with mac-address and computer which is connected to ip telephone can pass with 802.1x. I wondered that if there is same solution with wireless. 

    But it is not possible as you said, we should use one SSID for 802.1x, one SSID for MAC-auth, right?



  • 6.  RE: Clearpass MAC bypass before 8021.x with IAP

    EMPLOYEE
    Posted Feb 18, 2019 09:20 AM
    Correct.