Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

SHL Reference in Role Mapping

This thread has been viewed 2 times
  • 1.  SHL Reference in Role Mapping

    MVP
    Posted Jan 23, 2018 11:58 AM

    I have (2) static host lists setup for whitelisting devices on the wired network for MAC authentication. These are non-domain joined PCs that need to get to the production network, while other non-domain PCs (personal) should get denied access. Added the MAC addresses to each SHL with AB-CD-EF-AB-CD-EF format, which is what is sent in the "connection:client-mac-address" field and "radius-ietf:calling-station-id" field in the request. I've tried referencing both in my role mapping policy stating "Belongs_to_Group" and the SHL. Unfortunately, it is not acknowledging it. I'm using evaluate-all in my role mapping and it is recognizing it as a computer (based on category), but not as a whitelisted computer. Authentication is Allow All MAC Auth, since we are trying to also profile unknown devices, and devices that may not be present in the endpoints database.

     

    Am I missing something or is this just not supported? We're running 6.6.5.

     

    Thanks



  • 2.  RE: SHL Reference in Role Mapping
    Best Answer

    EMPLOYEE
    Posted Jan 23, 2018 12:20 PM

    Why aren't you using Device Registration? SHLs are not recommended.



  • 3.  RE: SHL Reference in Role Mapping

    MVP
    Posted Jan 24, 2018 10:45 AM

    Actually that is a good idea, didn't think of that originally.

     

    On a side note, the reference of "Connection:Client-Mac-Address" and "Radius-IETF:Calling-Station-Id" both work. Come to find out later, the MAC address in the SHL was not the one that was being tested, that's why it wasn't matching. Basically we tested a personal device, and not a whitelisted one.

     

    Thanks for the insight, I think I might setup something like MAC Trac for this, might make it easier.