Security

last person joined: 23 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

mac cache without self registration

This thread has been viewed 0 times
  • 1.  mac cache without self registration

    Posted Feb 26, 2014 01:10 PM

    Can you do mac caching without self registration on CP guest?



  • 2.  RE: mac cache without self registration

    EMPLOYEE
    Posted Feb 26, 2014 01:22 PM

    You can do device registration and have a user enter the MAC of the device and then leverage that for MAC auth port/SSID.



  • 3.  RE: mac cache without self registration

    Posted Feb 26, 2014 01:23 PM

    so the user enters the detail manually?



  • 4.  RE: mac cache without self registration

    EMPLOYEE
    Posted Feb 26, 2014 01:25 PM

    What is the scenario? Is this a click-through type setup, sponsored, etc?

     



  • 5.  RE: mac cache without self registration

    EMPLOYEE
    Posted Feb 26, 2014 01:28 PM

    Yes - the user would enter this manually using a URL you provide.   Once provided, that device can then connect to the intended SSID.



  • 6.  RE: mac cache without self registration

    Posted Feb 26, 2014 01:28 PM

    captive portal, authentication source - local db + active directory, post auth populate endpoints database with mac - send CoA, subsequent auth with mac.

     

    mac needs to be taken out of the portal redirect url, users typing this in themselves asking for trouble



  • 7.  RE: mac cache without self registration

    EMPLOYEE
    Posted Feb 26, 2014 01:31 PM
    There is a way of doing it and I'm in the process of testing our doc and updating. I hope to have it posted in a day or two.


  • 8.  RE: mac cache without self registration

    Posted Feb 26, 2014 01:40 PM

    Trouble I have is when I add AD as a secondary auth source it never seems to use it.  I am modifying a template



  • 9.  RE: mac cache without self registration

    Posted Feb 26, 2014 01:55 PM

    if there is any way I can assist in your testing please let me know



  • 10.  RE: mac cache without self registration

    Posted Feb 28, 2014 02:34 PM

    is this purely clear pass guest, so without policy manager? perhaps i have missed something but isnt this the usual clearpass guest + policy manager setup? first time normal login and then MAC caching kicks in?



  • 11.  RE: mac cache without self registration

    Posted Mar 01, 2014 03:40 AM
    After a conference call with tac we got it sorted. I will probably have to document a process flow chart for my own benefit and I'll post it up.