Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

VIA machine authentication

This thread has been viewed 2 times
  • 1.  VIA machine authentication

    Posted Dec 11, 2012 05:27 AM

    Hi

     

    I am running a trial of Aruba 3200 controllers with AP135s and have setup a 'corporate' SSID (802.1x EAP-PEAP/MSCHAPv2) using AD/NPS and enforcing machine authentication for our Windows based domain computers - this is all working as we wanted, only allowing valid domain computers to connect. We can then elevate user access using roles based on AD groups / policies in NPS.

     

    I would like to now achieve a similar setup with the VIA client. I have a working VIA configuration that I can attach to user roles and can use the VIA client to connect with my AD credentials, but I believe this will allow me to connect from any device with the VIA client installed.  Is there anyway I can easily restrict this to my valid domain computers (ideally without having to use a certificate infrastructure?)

     

    Thanks and regards,

    Adrian


    #3200


  • 2.  RE: VIA machine authentication

    MVP
    Posted Sep 10, 2014 03:52 AM

    I have to same requirement for a customer to do some sort of machine authentication on the VIA setup.

     

    This customer wants to control which users are allowed remote access (the easy part), but also limit the machines these users are allowed to set up the VPN connection from.

     

    Has anybody gotten anywhere regarding authentication machines with a VIA connection?



  • 3.  RE: VIA machine authentication

    EMPLOYEE
    Posted Oct 19, 2014 05:50 AM

    Guys, any update on this?  Have the same requirement and was going to start another thread, but found this one.

     

    EDIT, i found this http://community.arubanetworks.com/t5/Controller-Based-WLANs/Can-I-use-a-separate-authentication-mechanism-for-different/ta-p/180828