Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

H3LP | Unique-Device-Count GREATER_THAN 1) [Deny Access Profile] ....even after session over :(

This thread has been viewed 3 times
  • 1.  H3LP | Unique-Device-Count GREATER_THAN 1) [Deny Access Profile] ....even after session over :(

    Posted Oct 02, 2013 07:31 AM

    1. (Authorization:[Endpoints Repository]:Unique-Device-Count GREATER_THAN 1)  [Deny Access Profile]

     

     

    >ClearPass is keeping  denying even after user session is expired and deleted ..please advise.... i want to user to be able to connect only with 1 device for 1 hour.and his session is over he can re create a new user with the same e-mail and login with another (2nd device)



  • 2.  RE: H3LP | Unique-Device-Count GREATER_THAN 1) [Deny Access Profile] ....even after session over :(

    EMPLOYEE
    Posted Oct 02, 2013 08:12 AM

    Perhaps instead of just expiring the account...you can expire AND DELETE the account.  That way, the user can just re-create it with the same email.



  • 3.  RE: H3LP | Unique-Device-Count GREATER_THAN 1) [Deny Access Profile] ....even after session over :(

    Posted Oct 02, 2013 08:15 AM

    Thanks....BUTIt's already configured like this....

    Capture.PNG

    and it's aint working... when the 1 hour is over - i cant login with the same e-mail(user) with a 2nd device...

     



  • 4.  RE: H3LP | Unique-Device-Count GREATER_THAN 1) [Deny Access Profile] ....even after session over :(

    EMPLOYEE
    Posted Oct 02, 2013 08:17 AM

    Did you check the guest account after the hour?  Is it still there?



  • 5.  RE: H3LP | Unique-Device-Count GREATER_THAN 1) [Deny Access Profile] ....even after session over :(

    Posted Oct 02, 2013 08:19 AM

    yep  ...as expired....

    but the problem is that there is still endpoint record is still there even after the user account is expired....

     



  • 6.  RE: H3LP | Unique-Device-Count GREATER_THAN 1) [Deny Access Profile] ....even after session over :(

    EMPLOYEE
    Posted Oct 02, 2013 08:20 AM

    Yep...and that's the issue.  The account must also be deleted.  I'm wondering if it's a config issue or a bug.  Perhaps a TAC case?



  • 7.  RE: H3LP | Unique-Device-Count GREATER_THAN 1) [Deny Access Profile] ....even after session over :(

    Posted Oct 02, 2013 08:21 AM

    it's really freaking me out...

     

    i want the guest to be able to login for 1 hour with 1 device.

    but when the 1 hour is over...is account is expired...but his enpoint is still written...so if he trying to create a new account with the same user/e-mail with another devices...it's getting reject - even due...he his already finish his first 1 hour with his first device...



  • 8.  RE: H3LP | Unique-Device-Count GREATER_THAN 1) [Deny Access Profile] ....even after session over :(

    EMPLOYEE
    Posted Oct 02, 2013 08:26 AM

    FOr the Guest service you're using, can you check the post-auth actions?

     

    I see one here that may work for you...

     

    Screen Shot 2013-10-02 at 8.25.47 AM.png



  • 9.  RE: H3LP | Unique-Device-Count GREATER_THAN 1) [Deny Access Profile] ....even after session over :(

    Posted Oct 02, 2013 08:57 AM

    noop..that not what i looking for.

    the problem is with the endpoint record...and not with the expired guest 

     

     

    (i want the user to be able to log with 2nd device after the first 1 hour as passed and he finished to use is first device)

     



  • 10.  RE: H3LP | Unique-Device-Count GREATER_THAN 1) [Deny Access Profile] ....even after session over :(

    Posted Feb 19, 2014 09:48 AM

    Have you tried this setting?

     

    I'm facing the same problem with stale endpoints for old devices accumulating and causing users to exceed the unique-device-count.

     

    CPPM Endpoint Expiration



  • 11.  RE: H3LP | Unique-Device-Count GREATER_THAN 1) [Deny Access Profile] ....even after session over :(

    Posted Feb 26, 2014 08:30 AM

    I'll give it a try...

     

    1. (Authorization:[Endpoints Repository]:Unique-Device-Count GREATER_THAN 1)  [Deny Access Profile]

     

    You can't use this in your scenario - since that just counts the number of devices that is in the endpoint database connected with the same username.

    Or keep it there, but use a custom "Redirect profile" to Captive Portal, instead of the [Deny access profile].

     

    But ok - try first to remove that - and rely on a post_authentication enf.profile normally called "Guest Session Limit" if you create a MAC-auth service using the Wizard.

    That should disconnect the client if he has more than x active sessions. X is the number you've either set in Guest Manager, or manually edited for your self-registration.

     

    26.02.03.png

     

     Let me know how that works out :)