Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Mac book user+machine auth/ user+mac auth

This thread has been viewed 3 times
  • 1.  Mac book user+machine auth/ user+mac auth

    Posted Oct 16, 2015 08:13 AM

    HI,

     

    I am using User + Machine auth. for windows user and that is woring fine (SSID : Employee). Using self signed certificate.

    Now i have Mac book and they are the part of windows domain. 

     

    Can i use same SSID & enforcement policy for Mac Book? or if i add one more rule in the same enforcement policy --> User + mac auth.(static host list)

    EM service.jpg

    If not please suggest alternate more secure solution.

     

    Thanks in advance...

     

     



  • 2.  RE: Mac book user+machine auth/ user+mac auth

    EMPLOYEE
    Posted Oct 16, 2015 08:15 AM
    Yes, you can but it's a much more complex authentication as Macs do not natively perform machine authentication. 

    How are you managing your Macs? Profile manager or an MDM? 



    Thanks, 
    Tim


  • 3.  RE: Mac book user+machine auth/ user+mac auth

    Posted Oct 16, 2015 08:29 AM

    Thanks for quick reply....

     

    for system mac, i will use CPPM static host list.

     

    Regards,

    Nik..



  • 4.  RE: Mac book user+machine auth/ user+mac auth

    EMPLOYEE
    Posted Oct 16, 2015 08:31 AM
    You can only use MAC address as an authorization. The device still needs a machine credential to authenticate. 

    How are you managing the devices? 


    Thanks, 
    Tim


  • 5.  RE: Mac book user+machine auth/ user+mac auth

    Posted Oct 16, 2015 08:37 AM

    I will use windows AD for Mac book authentication.



  • 6.  RE: Mac book user+machine auth/ user+mac auth

    EMPLOYEE
    Posted Oct 16, 2015 08:38 AM
    How are you managing your devices? You need to be able to push a network profile down (or manually install on every single device) 


    Thanks, 
    Tim


  • 7.  RE: Mac book user+machine auth/ user+mac auth

    Posted Oct 16, 2015 08:47 AM

    Enforcement profile policy will push  vlan info to authenticated + authorize users.

    Please correct if i wrong..



  • 8.  RE: Mac book user+machine auth/ user+mac auth

    EMPLOYEE
    Posted Oct 16, 2015 08:52 AM
    You need a custom configuration profile installed on the devices to be able to do Machine + User authentication. 


    Thanks, 
    Tim


  • 9.  RE: Mac book user+machine auth/ user+mac auth

    Posted Oct 16, 2015 09:08 AM

    i can't do that on all mac book. Is there any alternate authentication method i can use instead of machine authentication?



  • 10.  RE: Mac book user+machine auth/ user+mac auth

    EMPLOYEE
    Posted Oct 16, 2015 09:10 AM
    You're not managing the devices? 

    User authentication with MAC address authorization or Onboard would be the alternatives. 


    Thanks, 
    Tim


  • 11.  RE: Mac book user+machine auth/ user+mac auth
    Best Answer

    Posted Oct 29, 2015 02:42 AM

    Hi,

     

    I have added new rule in the same enforcement profile using static host list. Add static host list group in authontication server list.

     

    Regards,

    Nik..