Security

last person joined: 23 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

How would an Aruba AP appear to the fingerprint function of ClearPass (wired MAC-auth)?

This thread has been viewed 0 times
  • 1.  How would an Aruba AP appear to the fingerprint function of ClearPass (wired MAC-auth)?

    Posted Sep 08, 2016 06:07 AM

    My customer would like to secure the wired port to which he is connecting an Aruba outdoor AP.  If you enabled MAC-auth on the host switch and also configured the default gateway to forward DHCP requests to ClearPass, how would the AP appear to the fingerprinting function in CPPM?  Would it be a unique enough device type to lock down that switch port not just to the MAC but to Aruba APs only?



  • 2.  RE: How would an Aruba AP appear to the fingerprint function of ClearPass (wired MAC-auth)?
    Best Answer

    EMPLOYEE
    Posted Sep 08, 2016 06:14 AM

    It would look like this:

    Screenshot 2016-09-08 at 05.12.59.png



  • 3.  RE: How would an Aruba AP appear to the fingerprint function of ClearPass (wired MAC-auth)?

    Posted Sep 08, 2016 06:20 AM

    Thanks Colin - that would present another hurdle, for users looking to simply plug in to the AP's switch port...   Could we write a CP rule that requires the device on that port to have the matching device name, too..?



  • 4.  RE: How would an Aruba AP appear to the fingerprint function of ClearPass (wired MAC-auth)?

    EMPLOYEE
    Posted Sep 08, 2016 06:30 AM

    You would have to compare it against a static mac address list of allowed APs.  Just checking for an Aruba AP would allow ANY Aruba AP to connect.



  • 5.  RE: How would an Aruba AP appear to the fingerprint function of ClearPass (wired MAC-auth)?

    Posted Sep 08, 2016 06:37 AM

    Sure; MAC-auth is my planned 'first barrier':

     

    1)  MAC auth against the installed APs MAC

    2) Permit only device name Aruba networks-AP-224 (or whatever the AP type happened to be)

    Thanks for your help, as always...   :)