Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

apple and android pulling 2 adress

This thread has been viewed 0 times
  • 1.  apple and android pulling 2 adress

    Posted Jan 22, 2015 02:13 PM

    the apple device or android will still utilize the last ip address it attached to most likely the users home address 10.0.0 or 192. x
    The issue is it is using up address in a scope that is in my dmz on the 10 network ( don't yell at me some idiot used it as my dmz 10 years ago long before I worked here) I will be moving it asap. but for now, is there anything I can do to prevent this from happening

     

     

    (psd-master01) #show  user | include  10:1c:0c:2a:2a:1b
    10.0.0.10       10:1c:0c:2a:2a:1b                             psd-guest-logon    00:00:01                    AP-RM-211.Floor 1.100.GHH                  Wireless  psd-open/d8:c7:c8:f7:39:28/a-HT    psd-open    tunnel        iPad           
    10.50.146.61    10:1c:0c:2a:2a:1b                             psd-guest-logon    00:00:01                    AP-RM-211.Floor 1.100.GHH              Wireless  psd-open/d8:c7:c8:f7:39:28/a-HT    psd-open    tunnel        iPad 

     

    (psd-master01) #show  user | include  84:38:35:97:a5:59
    10.10.129.18    84:38:35:97:a5:59  84383597a559               psd-authenticated  00:01:34    MAC             ESC_SWITCH_ON_BENCH                        Wireless  psd-secure/ac:a3:1e:9a:3d:11/a-HT   psd-secure  tunnel        iPhone    
    172.24.25.144   84:38:35:97:a5:59  84383597a559               psd-authenticated  00:01:34    MAC             ESC_SWITCH_ON_BENCH                     Wireless  psd-secure/ac:a3:1e:9a:3d:11/a-HT  psd-secure  tunnel        iPhone    

     



  • 2.  RE: apple and android pulling 2 adress

    EMPLOYEE
    Posted Jan 22, 2015 02:14 PM
    If you are not using the 192 space, you can add a deny rule for that subnet to the validuser acl. 


    Thanks, 
    Tim


  • 3.  RE: apple and android pulling 2 adress

    Posted Jan 22, 2015 02:17 PM

    Try that dosnt work



  • 4.  RE: apple and android pulling 2 adress

    Posted Jan 22, 2015 02:18 PM

    Tried that dosn't work



  • 5.  RE: apple and android pulling 2 adress

    EMPLOYEE
    Posted Jan 22, 2015 02:22 PM
    Do you have enforce-dhcp enabled in your AAA profile?


  • 6.  RE: apple and android pulling 2 adress

    Posted Jan 22, 2015 02:23 PM
    Edit: Cappalli already suggested that


  • 7.  RE: apple and android pulling 2 adress

    Posted Jan 22, 2015 09:00 PM
    Add the segments you want to allow on the controller to the valid user ACL. Search for valid user on the community.


  • 8.  RE: apple and android pulling 2 adress

    Posted Jan 22, 2015 09:04 PM
    All other segments will be denied