Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Guest vs Eterprise licenses

This thread has been viewed 0 times
  • 1.  Guest vs Eterprise licenses

    Posted Jan 15, 2017 12:41 PM

    Hello,

     

    A customer has ClearPass cluster that is utilising only Guest services. It is expected that any connected device will use up two licenses, one guest and one core (Policy Manager). However, we are observing tenfold higher use of core ones, compared with guest.

     

    Am I getting all this about licensing wrong, or are we having an issue? Thanks in advance.

     

     

    NesaM



  • 2.  RE: Guest vs Eterprise licenses

    EMPLOYEE
    Posted Jan 15, 2017 12:45 PM

    What vendor is the NAD?
    Are you sending back an ACCEPT or REJECT to get users into a captive portal state?



  • 3.  RE: Guest vs Eterprise licenses

    Posted Jan 15, 2017 03:43 PM

    Hi Tim,

     

    Customer is using Aruba MC, Guest services are standard one (Guest MAC Auth , and Guest Access with MAC caching), and they are using "Allow Access" as default profile for Guest MAC Auth Enforcement Policy.

     

    Thanks.

     

    NesaM



  • 4.  RE: Guest vs Eterprise licenses

    EMPLOYEE
    Posted Jan 15, 2017 03:50 PM
    It's likely drive-bys or users who connect and then never register.


  • 5.  RE: Guest vs Eterprise licenses

    EMPLOYEE
    Posted Jan 15, 2017 03:50 PM
    It's likely drive-bys or users who connect and then never register.


  • 6.  RE: Guest vs Eterprise licenses

    Posted Jan 15, 2017 03:55 PM

    Thanks TIm,

     

    Is there any way of by-passing this by changing Enforcement policy somehow? Customer's worry is that they will run out of core licenses quite easily if they roll out Guest access to more locations/campuses (forgot to mention this is Higher Education establishment).

     

    Thanks.

    NesaM



  • 7.  RE: Guest vs Eterprise licenses
    Best Answer

    EMPLOYEE
    Posted Jan 15, 2017 03:58 PM
    Yes, send a REJECT for unknown devices and make sure your initial role in the AAA profile is the captive portal role.


  • 8.  RE: Guest vs Eterprise licenses

    Posted Jan 25, 2017 06:06 AM

    Hi Tim,

     

    After a week of monitoring the situation, I can confirm that this worked. Thanks for the advice.

     

     

    Regards,

    NesaM



  • 9.  RE: Guest vs Eterprise licenses

    EMPLOYEE
    Posted Jan 15, 2017 03:58 PM
    Yes, send a REJECT for unknown devices and make sure your initial role in the AAA profile is the captive portal role.


  • 10.  RE: Guest vs Eterprise licenses

    Posted Jan 15, 2017 04:00 PM

    Thanks, I will get on with it and let yu know of a result.

     

    NesaM



  • 11.  RE: Guest vs Eterprise licenses

    EMPLOYEE
    Posted Jan 15, 2017 12:45 PM
    What vendor is the NAD?
    Are you sending back an accept or deny to get users into a captive portal state?