Security

Reply
Highlighted
New Contributor

What are my options to stop employees from using Guest access?

I am looking for any ideas on how to setup/configure our guest network so it limits employees from using it. Currently we have Clearpass in place and will be setting up airwave.

 

 


Accepted Solutions
Highlighted
Aruba Employee

Re: What are my options to stop employees from using Guest access?

I'm not sure which Guide/Post Tim is referring to here, but here is a little tidbit...

 

RADIUS Deny Access on the MAC Caching profile will trigger the client to get the default AAA role on the controller (captive portal).

 

RADIUS Drop Access on the MAC Caching profile will drop the user from that SSID. No default AAA profile, no captive portal.

 

Hope that helps.

 

 

Thanks,

Zach Jennings

View solution in original post


All Replies
Highlighted
Moderator

Re: What are my options to stop employees from using Guest access?

You can set a custom attribute in the database once they connect to your secure network to stop them from going back to the guest network.


Thanks,
Tim


If this response is more than 1 year old, it may no longer be accurate. Please consult official Aruba documentation, TAC or your Aruba SE.

| Aruba Alumni | @timcappalli | timcappalli.me |

Highlighted
New Contributor

Re: What are my options to stop employees from using Guest access?

Tim,

Thanks for your reply. Would I want to add the custom attribute in the mobility controller or clearpass?

 

Thanks,

Jake

Highlighted
Moderator

Re: What are my options to stop employees from using Guest access?

ClearPass. Take a look at the guide in the post above.


Thanks,
Tim


If this response is more than 1 year old, it may no longer be accurate. Please consult official Aruba documentation, TAC or your Aruba SE.

| Aruba Alumni | @timcappalli | timcappalli.me |

Highlighted
Aruba Employee

Re: What are my options to stop employees from using Guest access?

I'm not sure which Guide/Post Tim is referring to here, but here is a little tidbit...

 

RADIUS Deny Access on the MAC Caching profile will trigger the client to get the default AAA role on the controller (captive portal).

 

RADIUS Drop Access on the MAC Caching profile will drop the user from that SSID. No default AAA profile, no captive portal.

 

Hope that helps.

 

 

Thanks,

Zach Jennings

View solution in original post

Highlighted
Moderator

Re: What are my options to stop employees from using Guest access?

Guess it didn't post.

http://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/Guide-Using-ClearPass-to-steer-users-to-secure-networks-mhc/td-p/144823


Thanks,
Tim


If this response is more than 1 year old, it may no longer be accurate. Please consult official Aruba documentation, TAC or your Aruba SE.

| Aruba Alumni | @timcappalli | timcappalli.me |

Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: