Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

MAC caching on ClearPass

This thread has been viewed 8 times
  • 1.  MAC caching on ClearPass

    Posted Jul 14, 2020 06:17 AM

    Hi, 

     

    Is it best practice to have a separate service to handle mac caching within ClearPass or to include it within the same service? I have the following condition within a role mapping policy, all within one service. 

    3.(Authorization:[Time Source]:Now Plus 1day  EXISTS   )[MAC Caching]

    Please advise.  

     

    Adam



  • 2.  RE: MAC caching on ClearPass
    Best Answer

    EMPLOYEE
    Posted Jul 14, 2020 08:43 AM

    MAC Caching consists of two parts:

    - A WEBAUTH that handles the captive portal authentication and injects timestamps into the endpoint database.

    - A MAC Authentication service and leverages the timestamps injected during captive portal authentication.

     

    Best-practice is to have two separate services for these as MAC Auth in general is done in a separate service from user authentication services.

     

    Does this answer the question, or did I miss the point?



  • 3.  RE: MAC caching on ClearPass

    Posted Jul 16, 2020 11:13 AM

    Thanks for this reply. 

     

    We actually have an interface where users can register their device mac address and receive an MPSK. 

     

    Does the the two service model still apply to this scenario?

     

    Thanks  



  • 4.  RE: MAC caching on ClearPass

    MVP EXPERT
    Posted Jul 16, 2020 11:28 AM

    This is IoT/headless registration? You should use the MPSK service template.



  • 5.  RE: MAC caching on ClearPass

    Posted Jul 16, 2020 11:34 AM

    Yes - that's right IoT registration. 

     

    Good - that's what we're currently using. It was to double check we were going about it the correct way. 

     

    Thanks