Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass With Student Devices that dont support 802.1x

This thread has been viewed 5 times
  • 1.  Clearpass With Student Devices that dont support 802.1x

    Posted Oct 01, 2018 02:15 PM

    Hello, I have some questions about student devices in dorm rooms and how some other people handle these types of situations.
    We currently have 2 SSID's. The primary 802.1x ssid authenticating to clearpass/Active Directory, and an open guest network for guests and devices that dont support 802.1x like xbox's, roku's, playstations stuff like that. We have dhcp fingerprinting rules in place that detect if they are game consoles or home entertainment devices and automatically take then and assign them to the student network while the regular guests stay in the guest network. This works really well from a technical standpoint but its kind of not intuitive and since students dont like to read our instructions for which devices go on which network we get lots of work orders for this. Additionially since its an open network its not very secure. I would prefer to move these devices over to a secure network and leave the guest network for actual guests.
    It sounds like EAP-PWD is a better more secure version of WPA-PSK but i cant see to find much in the way of documentation for it. I cant even seem to find much on the way of client support for the standard. Do typical consumer devices like the ones mentions support this? Does anyone ahve a guide on how to actually configure this with Aruba Controllers and Clearpass? I see basic notes for it but not how to actually make it work.

    Additionally, what do other users for this? I would be interested to know what other org's do in this scenario. I would prefer to avoid having them register their devices in clearpass and that seems to be kind of a pain and not a great user experience. Ideally i thing my dream is a SSID that is locked down and the only way to get connected to it is via dhcp fingerprinting. Other devices such as phones would connect to the 802.1x network and then real guests would go register on the captive portal.

    Thanks in advance, i am very curious to see what others have ended up doing for their students.



  • 2.  RE: Clearpass With Student Devices that dont support 802.1x

    Posted Oct 01, 2018 03:00 PM
    You best option for headless devices is to use ClearPass device registration workflow, see here:
    https://community.arubanetworks.com/t5/Unlisted-1/How-To-Advanced-Device-Registration-in-ClearPass-November-MHC/td-p/217291

    With this option you will be using Mac authentication and it also gives the flexibility to students to register and manage their own devices

    Thank you

    Victor Fabian

    Pardon typos sent from Mobile


  • 3.  RE: Clearpass With Student Devices that dont support 802.1x

    EMPLOYEE
    Posted Oct 01, 2018 03:40 PM
    EAP-PWD is a form of 802.1X which most these devices do not support. As Victor mentioned, use either an open or PSK network with Device Registration.


  • 4.  RE: Clearpass With Student Devices that dont support 802.1x

    Posted Aug 20, 2019 03:27 PM

    Guys,

     

    Am i the only one that can no longer open this link?  If so do you know if there is another resource where i can find these details now.

     

    Thanks,

     

    Jeff

     



  • 5.  RE: Clearpass With Student Devices that dont support 802.1x

    Posted Mar 02, 2020 11:42 AM

    I can't open it either.

    Access Denied


  • 6.  RE: Clearpass With Student Devices that dont support 802.1x

    Posted Mar 02, 2020 02:48 PM