Security

last person joined: 16 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

MAC auth and WinPE boot building a computer

This thread has been viewed 1 times
  • 1.  MAC auth and WinPE boot building a computer

    Posted Oct 30, 2018 03:49 PM

    Our current setup does not allow us to boot into a USB WinPE environment to build computers on NAC enabled switchports. Is there a way to add a custom attribute that Clearpass will recognize in a WinPE boot environment and allow the machine to MAC auth so it can temporarily reach an image deployment server? Our workaround is to remove the NAC configuration from switchports.



  • 2.  RE: MAC auth and WinPE boot building a computer

    Posted Oct 31, 2018 03:19 AM

    Do you use network boot, i.e. PXE ?
    If so you can use the category "Network Boot Agent" in you Macauth Policy to handle this.



  • 3.  RE: MAC auth and WinPE boot building a computer

    Posted Oct 31, 2018 12:42 PM

    No, we are using a thumb drive  to boot into a WindowsPE OS, which then connects to a network share to pull down the image file



  • 4.  RE: MAC auth and WinPE boot building a computer

    Posted Oct 31, 2018 01:06 PM

    If you know the mac address of the computer you could add it to a static mac list and create a rule to allow it to authenticate to install the image.

     

    You can remove the mac address afterwards from the static list.

     

    I would use MDT/pxe boot for that and not bother with a USB drive



  • 5.  RE: MAC auth and WinPE boot building a computer

    Posted Oct 31, 2018 02:44 PM

    You could also redirect the unknown WinPE to a portal for authentifaction, or just allow the boot file from unknown connections (not the best, but it could work)



  • 6.  RE: MAC auth and WinPE boot building a computer

    Posted Nov 06, 2018 01:42 PM

    Can someone give me guidance on setting up a portal for authentication? Sorry I have no experience in that area. Can that be done in CPPM? Basically I would need the portal to authenticate a user from a specific AD container and allow network access so the machine can pull down its image. Thanks in advance!!



  • 7.  RE: MAC auth and WinPE boot building a computer

    EMPLOYEE
    Posted Nov 06, 2018 01:44 PM
    Take a look at the ClearPass Solution Guide for Wired Policy Enforcement.


  • 8.  RE: MAC auth and WinPE boot building a computer

    Posted Mar 29, 2019 05:05 PM

    I can't seem to find network boot agent anywhere, would that be in the Role Map of my MAC service?



  • 9.  RE: MAC auth and WinPE boot building a computer

    Posted Apr 01, 2019 10:42 AM

    network boot agent?

     

    Booting a computer onto something like Microsoft Deployment Toolkit so you can deploy images to the computer would be separate from Clearpass.

     

    You would allow the computer onto the network using clearpass and it would pick up network boot from DHCP in conjunction with something like MDT.