Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Machine Authenticate issue.

This thread has been viewed 7 times
  • 1.  Machine Authenticate issue.

    Posted Aug 31, 2016 05:10 AM
     Dear everybody,

     

    I have configured CP integrate with HP 2530-24G switch for authenticating and I meet this issue:

       CP had joined domain, HP switch had configured for port access authen, everything is work but when I configure Machine Authenticate with the guide from this community and issue happen:

        - If laptop hadn't join domain so CP did not show Machine Authenticated. Of course.

        - If laptop joined domain, CP will always show Machine Authenticated even when I login to laptop by local user.

     

    I want to create the policy to block user access the network if they do not login to their user domain but it will not work if CP always show Machine Authenticated.

     

    Could anybody help me on this issue!

     

    Thanks.

     


  • 2.  RE: Machine Authenticate issue.

    Posted Aug 31, 2016 05:24 AM
    What you need to do is send a GPO with the wireless profile set the Authentication mode to "user or computer" and to "Automatically use my Windows logon name and password"

    https://msdn.microsoft.com/en-us/library/dd759176(v=ws.11).aspx

    This should help you with that issue

    Get Outlook for iOS


  • 3.  RE: Machine Authenticate issue.

    EMPLOYEE
    Posted Aug 31, 2016 05:27 AM

    If a mac address has machine authenticated, by default the result is cached for 24 hours.  The parameter that controls that behavior is under Administration> Server Manager> Server Configuration> Click on Server> Service Parameters> Select Policy Server Service:

    machine-auth.png

    Alternatively, you can clear the machine authentication cache manually by clicking on Administration> Server Manager> Server Configuration> Clear Machine Authentication Cache:

    cache2.png

     

    The reason the cache is in place is because machine authentication only happens when the machine is sitting at the ctrl-alt-delete screen, either because it just rebooted, or because someone logged out.  Many people do not log out of their computers, however  and just lock them.  When they wake their computers up, machine authentication does not take place, so CPPM will think that it is not a domain machine.  The machine authentication cache stores the previous authentication and renews it, every time there is a successful authentication, so that the user does not have to reboot or logout of their machine to demonstrate that this is a domain machine.  I hope this helped.



  • 4.  RE: Machine Authenticate issue.

    Posted Sep 13, 2016 04:42 AM

    Dear C

     

     



  • 5.  RE: Machine Authenticate issue.

    EMPLOYEE
    Posted Sep 13, 2016 05:03 AM

    You should be looking in the Access Tracker, under the Summary Tab.  Under "Roles", it should say [Machine Authenticated] and [User Authenticated].  Please post a screenshot of both access tracker messages.

     



  • 6.  RE: Machine Authenticate issue.

    Posted Sep 13, 2016 05:30 AM

    Dear Cjoseph,

     

    Please kindly check the image below.

    1.PNG

    2.PNG

    3.PNG

     

    Hera are the configuration for HP Wire with Onguard and Guest service:

    4.PNG

    5.PNG

    6.PNG

    Thank you.

     

     



  • 7.  RE: Machine Authenticate issue.

    Posted Sep 13, 2016 05:45 AM

    Dear Cjoseph,

     

    Please kindly check the images below:

    1.PNG2.PNG3.PNG

     

    Here are the configuraiton on ClearPass:4.PNG5.PNG6.PNG

    Thank you.



  • 8.  RE: Machine Authenticate issue.

    Posted Sep 13, 2016 05:59 AM

    Dear Cjoseph,

     

    I upload the image and receive the email from airheads that I earn the badge for upload pictures but when I refresh to check it not show my post. So I upload it to my onedrive, please kindly check the link below:

    Link 1

    Link 2

    Link 3

    Below is the image for configuration of CP

    Link 4

    Link 5

    Link 6

    Thank you.



  • 9.  RE: Machine Authenticate issue.

    EMPLOYEE
    Posted Sep 13, 2016 06:05 AM

    Do you also have Onguard Installed?

    It says that System Posture Status is Infected.



  • 10.  RE: Machine Authenticate issue.

    Posted Sep 13, 2016 06:17 AM

    Dear Cjoseph,

     

    Yes, I have Onguard install. 

    I just disable Onguard service and retest again. It still show machine authenticated when pc boot to logon screen and not show machine authenticated when login by domain account as the image that I post in the last reply.

    Do you have any advice?

     

    Thank you.



  • 11.  RE: Machine Authenticate issue.

    EMPLOYEE
    Posted Sep 13, 2016 06:33 AM

    In your enforcement policy in your service, check to see if "Use Cached Results" is enabled.

     

    cached.png



  • 12.  RE: Machine Authenticate issue.

    Posted Sep 13, 2016 09:38 PM

    Dear Cjoseph,

     

    Yes, it's enable. I try to disable and test but the role in access tracker still not show Machine Authenticated when login via account domain.

    Could you export your configuration and share it to me for testing?

     

    Thank you.



  • 13.  RE: Machine Authenticate issue.

    EMPLOYEE
    Posted Sep 13, 2016 09:57 PM

    My lab does not have any machine authentication, messages and it is not using wired authentication.  What version of CPPM are you using?



  • 14.  RE: Machine Authenticate issue.

    Posted Sep 13, 2016 10:10 PM

    Dear Cjoseph,

     

    I'm using CPPM 6.6.1.84176

    I export my configuration as attachment, please kindly look around if I configure any wrong.

     

    Thank you.

    Attachment(s)

    zip
    Service.zip   5 KB 1 version