Wireless Access

last person joined: 16 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Aruba guest user attacks ?

This thread has been viewed 0 times
  • 1.  Aruba guest user attacks ?

    Posted Feb 05, 2016 10:34 AM

    We are using capitive portal for guest users. Now if the user is smart, they could find the address of the controller and then try to directly logon to controller. Now we always change the username and password from the aruba defaults so even if they are smart enough to try to log onto the controller there is a very slim change that they would be able to do so. That being said (and this is my real questoin) is there a way for the controller to block access to the web-gui log on after say 5 bad username password attempts?

     

    Thought about using blacklist after x amount of failed login attempts but thinking that only applies to wifi client logon so not sure that is going to help me.

     

    Anyone have an idea?  Do you think it is really a concern or is my security guy just going a bit overboard on me?

     

    Suggestions comments welcomed...    

     



  • 2.  RE: Aruba guest user attacks ?
    Best Answer

    EMPLOYEE
    Posted Feb 05, 2016 10:36 AM
    You should block ports 22 and 4343 in your user-roles to prevent this.


  • 3.  RE: Aruba guest user attacks ?

    Posted Feb 05, 2016 10:39 AM

    That should work.  Thanks Tim.