Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Mac caching and unknown Endpoint

This thread has been viewed 0 times
  • 1.  Mac caching and unknown Endpoint

    Posted Oct 11, 2016 02:31 PM

    Hello Community. 

     

    I have a customer how wants to authorize his clients manualy. For that i check in the service if the endpoint is known and we use PEAP. He manualy marks the endpoints as know. That works fine for him.

     

    Now we have a problem with mac caching. When a guest logs in the Wifi the Guest is marked as a known device that mac caching works. When i remove the update endpoint from the enforcement policy mac caching is no longer working. 

     

    Does anybody has a idea how to realize that?

     

    Regards Stefan

     



  • 2.  RE: Mac caching and unknown Endpoint

    EMPLOYEE
    Posted Oct 11, 2016 02:33 PM
    I'd recommend you look at using the Guest Device Repository for handling
    known device registration.


  • 3.  RE: Mac caching and unknown Endpoint

    Posted Oct 11, 2016 03:48 PM

    Hello, that sounds good. But i don´t understand how i can add a device in Guest User Repository and how can i check this? In CPPM i find nothing. 



  • 4.  RE: Mac caching and unknown Endpoint

    EMPLOYEE
    Posted Oct 11, 2016 03:50 PM
    Under guest, go to Create Device.


  • 5.  RE: Mac caching and unknown Endpoint

    Posted Oct 11, 2016 03:53 PM

    Ok, but is it possible to create this automaticly when the guest is authenticaed?



  • 6.  RE: Mac caching and unknown Endpoint

    EMPLOYEE
    Posted Oct 11, 2016 03:56 PM
    Sorry, looks like we're talking about different things.



    You don't have to mark guests as Known. Instead you can change your
    MAC-caching service to do Allow All MAC-Auth and remove the Update Endpoint
    Known action.


  • 7.  RE: Mac caching and unknown Endpoint

    Posted Oct 11, 2016 04:20 PM

    I think so. Ok, i have to create a new enforcement Profile an allow all Mac? Is that also a Post_Authentication Endpoint Atribute?

     

     



  • 8.  RE: Mac caching and unknown Endpoint

    EMPLOYEE
    Posted Oct 11, 2016 04:34 PM
    No, it's the authentication method in your MAC-Auth service.


  • 9.  RE: Mac caching and unknown Endpoint

    Posted Oct 11, 2016 04:44 PM

    Ok, this is at the moment at Endpoint Repository. And i have to change it to? 



  • 10.  RE: Mac caching and unknown Endpoint
    Best Answer

    EMPLOYEE
    Posted Oct 11, 2016 05:08 PM
    That should be the auth source. Above that, you should have Auth Methods.
    Remove MAC Auth and replace with Allow All MAC Auth


  • 11.  RE: Mac caching and unknown Endpoint

    Posted Oct 11, 2016 05:38 PM

    Perfekt. It works. 

     

    Thank you very much :)

     

    Regard Stefan