Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

MAB for Printer Only ACCESS in ClearPass

This thread has been viewed 7 times
  • 1.  MAB for Printer Only ACCESS in ClearPass

    Posted Feb 20, 2020 12:18 AM

    Hi,

    I would like to know i want to allow MAC of Printer only in clear pass.

    is it possible ?

    for example don't want to allow computer MAC and Phone MAC in MAB authentication ?

    if it is can with method should i used and let me know the reference guide?



  • 2.  RE: MAB for Printer Only ACCESS in ClearPass

    EMPLOYEE
    Posted Feb 20, 2020 03:50 AM
      |   view attached

    In MAC Authentication service rule try set Device> Device Type > Printer and check. If incoming authentication request coming from Device Printer, request will fall in to this this categorization service.

     

     

     

     

     



  • 3.  RE: MAB for Printer Only ACCESS in ClearPass

    Posted Feb 20, 2020 08:40 PM

    Hi,

    It is mean clearpass can device type which connected to network ?

    let me know it can detect computer also ?

    I mean i want to detect computer and printer.

    if it is computer used 802.1x and if Printer use MAB.

    ClearPass can detect computer or printer ?

    can we authenticate both MAB and 802.1x in one profile ?

    I mean if it is computer i want to use MAB and 802.1x together.After MAB passed ,continues check with 802.1x ?

    Example:

    check    MAB ==> passed==>check 802.1x ===>Passed

    if check MAB ==>fail ==>deny 

    I cannot not use above method ?

    if it is can let me know reference ?



  • 4.  RE: MAB for Printer Only ACCESS in ClearPass
    Best Answer

    EMPLOYEE
    Posted Feb 21, 2020 05:43 AM

    If you have clearpass server go to Configuration » Identity » Endpoints  to see classification info of endpoint devices.

     

    We need to enable profiler in service to get more device details. Client can not do MAC and .1x authentication at same time.