Security

last person joined: 2 days ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Guest MAC Caching value change

This thread has been viewed 5 times
  • 1.  Guest MAC Caching value change

    Posted Apr 08, 2016 06:27 PM

    Hi Forum,

     

    I'm trying to see if I can change that clearpass guest MAC caching to something less that 24 hours. I'm looking for 4 hours time period for MAC caching after guest account is created and then to not allow access after the 4 hours or redirect back to the captive portal. My guest account are only valid for 4 hours but MAC caching still works for 24 hours.

     

    thanks,



  • 2.  RE: Guest MAC Caching value change

    EMPLOYEE
    Posted Apr 08, 2016 06:34 PM
    Is your MAC-caching set up to use the value from the guest account or a
    custom time source value?


  • 3.  RE: Guest MAC Caching value change

    Posted Apr 08, 2016 06:38 PM

    Tim, this is what I have in the role mapping for mac caching:

     

    Screen Shot 2016-04-08 at 3.36.10 PM.png



  • 4.  RE: Guest MAC Caching value change

    EMPLOYEE
    Posted Apr 08, 2016 06:40 PM
    Please post the enforcement policy from your web auth service and the
    contents of the enforcement profile that is setting the MAC-auth expiry.


  • 5.  RE: Guest MAC Caching value change

    Posted Apr 08, 2016 06:48 PM

    below:

     

    Screen Shot 2016-04-08 at 3.41.51 PM.png

     

     

    Screen Shot 2016-04-08 at 3.44.51 PM.png

    I see it say one day DT but ot sure how to set it up to less.



  • 6.  RE: Guest MAC Caching value change
    Best Answer

    EMPLOYEE
    Posted Apr 08, 2016 07:00 PM

    You're manually setting a time for the expiration. If you want it to match what is set on the guest account, change that value to:     %{Authorization:[Guest User Repository]:ExpireTime}



  • 7.  RE: Guest MAC Caching value change

    Posted Apr 08, 2016 07:02 PM

    I will change and test. honestly I'm not "manually" setting anything. I just used the template and that was created.



  • 8.  RE: Guest MAC Caching value change

    EMPLOYEE
    Posted Apr 08, 2016 07:04 PM
    You may have selected "One Day" during the wizard instead of "Account Expiry
    Time".


  • 9.  RE: Guest MAC Caching value change

    Posted Apr 08, 2016 07:07 PM

    Correct. I did that.

     

    Thanks for the help.