Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Need assistance with adding MAC caching and authentication for guests

This thread has been viewed 2 times
  • 1.  Need assistance with adding MAC caching and authentication for guests

    Posted Apr 30, 2014 05:51 PM

    I have integrated my guest SSID on my controller with ClearPass Guest authentication and that appears to be working.  I want to add mac caching and mac authentication for guest users, so that they don't have to reauthenticate every time their device wakes up, or they reconnect to the guest WLAN.  I'd like to give them an 8 hour window where they can reauthenticate using their cahed mac address, rather than using a username and password.  I wasn't quite sure how to accomplish what I want to do, so I disabled my working guest access service and used the service template, Guest MAC Authentication, to create a new service.  This appears to create two new services:Guest MAC Authentication, and Guest Access with MAC Caching.  I am not certain what each of these new services does, or how to modify them to accomplish my task.

     

    Any assistance, or configuration documentation would be greatly appreciated.



  • 2.  RE: Need assistance with adding MAC caching and authentication for guests



  • 3.  RE: Need assistance with adding MAC caching and authentication for guests
    Best Answer

    Posted May 01, 2014 06:10 PM
    Aruba controller? First you add mac auth profile (dash separator is fine) and mac auth server (clearpass) in your guest- AAA profile.
    Second adjust the ssid name in the two new services the wizard created.
    -》Done! There is some more tweaking you can do, but at this stage it will work.


  • 4.  RE: Need assistance with adding MAC caching and authentication for guests

    Posted May 05, 2014 04:37 PM

    Thank you, John.  It took some fiddling, but I was able to get this working.  I will have to tinker a bit more when I have some time, but for now MAC Auth appears to be functioning.