Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

MAC spoofing protection not working

This thread has been viewed 2 times
  • 1.  MAC spoofing protection not working

    Posted Oct 23, 2013 03:10 PM

    a while ago i checked about MAC spoofing protection, recently i had some time to test it out but it doesnt function as hoped.

     

    im testing with fixed device which is profiled (IP helper set to clearpass) correctly, then i take my laptop with the linux backtrack distribution spoof the MAC and try to authenticate, both use DHCP.

     

    two things are unclear / broken for me.

     

    1) how do i act on device conflict? i can't turn on the profiling tab, set it to CoA disconnect when status is conflict. but nowhere i can find when this conflict condition occurs. i had expected to see something in the endpoint database but there i find nothing. it also doesn't seem to work, but the reason is unclear, doesn't a conflict occur or is it something else?

     

    2) when i start with the linux laptop and afterwards plugin the other device the entry in the endpoint database is updated correctly (all fields i mean, hostname, category and such, no mention of conflict, the entry is just "overwritten"). but when i start with the other device and then the linux laptop only the hostname changes, the rest like the OS and type remain the original one. to me this is not expect behavior right? anyone ran into a bug here?



  • 2.  RE: MAC spoofing protection not working

    EMPLOYEE
    Posted Oct 23, 2013 09:43 PM

    I will have to test this in my lab when I get back and get back to you. 

     

    Your enforcement policy should have a condition stating something like what I have below, but in my example Im putting the device in a dead end vlan instead of a reject. If I send a reject the user or device could just keep trying to connect and get rejected. This way I can control the user after they try to trick the system.

     

    conflict.png

     

     



  • 3.  RE: MAC spoofing protection not working

    Posted Oct 24, 2013 02:54 PM

    thanks tarnold, your rule makes sense but again is based on the conflict category which i can't seem to get in the end point database. not even when changing from a linux laptop to the device we use, pretty much everything but the MAC changes, still there is no hint of a conflict.



  • 4.  RE: MAC spoofing protection not working

    Posted Nov 06, 2013 02:28 PM

    also opened a ticket with support, they told me to enable the audit tab. done this and see the nmap scan happening, but no further effect. i also fail to see anywhere what the result is.

     

    i found the ancient document on the support site, but i fails to connect all the dots:

    http://support.arubanetworks.com/DOCUMENTATION/tabid/77/DMXModule/512/Command/Core_Download/Default.aspx?EntryId=6884



  • 5.  RE: MAC spoofing protection not working

    Posted Nov 13, 2013 10:03 AM

    boneyard - have you gotten anywhere with your case? I'm running into the same issue. 



  • 6.  RE: MAC spoofing protection not working

    Posted Nov 14, 2013 01:26 PM

    not yet, support is working on it. if it gets worked out ill certainly report back here.

     

    as i said, audit needs to be turned on and the devices need to be audited correctly, the policy simulation is the way to test this.

     

    in the mean time im certainly interested in people who have made this work at some time.



  • 7.  RE: MAC spoofing protection not working

    Posted Feb 26, 2014 03:12 PM

    so, three months later and still not working.

     

    went from audit to profiling and back to audit, but not succes. it seems we are close because the scan and / or profiling does detect different devices, clearpass just doesnt act on it.

     

    seeing how this doesnt pick up any replies makes me believe no one is using it anyway :)



  • 8.  RE: MAC spoofing protection not working

    MVP
    Posted Dec 08, 2015 01:49 PM

    Boneyard - I know this is an old thread, but ever come up with a fix for this?



  • 9.  RE: MAC spoofing protection not working

    Posted Dec 13, 2015 05:04 AM

    it has been some time ago but i believe the was a bug which was fixed in later versions. so the original suggestion from tarnold with the conflict category should work now. im not sure if i ever gotten around to test it later on. i have a PoC coming up soon and will see if i can slip this in :)



  • 10.  RE: MAC spoofing protection not working

    Posted Jan 09, 2016 05:33 AM

    for me the conflict status doesn't work, but i might be using it wrong, i posted my reply in the thread below and will continue updates there:

     

    http://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/Device-conflict/td-p/201891