Security

 View Only
last person joined: 18 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

How Clearpass sets up authentication based on device type

This thread has been viewed 38 times
  • 1.  How Clearpass sets up authentication based on device type

    Posted May 02, 2022 10:07 AM
    Our company was recently preparing to deploy the Clearpass and is now in trouble.  Since there are many devices like Avaya phone that cannot be 802.1x certified, and  establishing MAB certification is a huge challenge for us. And we cannot confirm which port it conected, So we can't cancel the configuration of authentication on the switch interface. How do I set up admission based on the type of device? Its purpose is to authenticate devices like Avaya phones that cannot perform 802.1x.

    ------------------------------
    Hevin Huo
    ------------------------------


  • 2.  RE: How Clearpass sets up authentication based on device type

    EMPLOYEE
    Posted May 03, 2022 07:03 AM
    Start here:  https://asp.arubanetworks.com/downloads/documents/RmlsZTpmMDY3Y2UwYS1lNmZiLTExZWEtYjFjMi0zYmZjN2Y0MzMxNDI%3D

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------



  • 3.  RE: How Clearpass sets up authentication based on device type

    Posted May 03, 2022 10:37 AM
    You can try - Connection: Client-Mac-Vendor equals AVAYA = Role mapping...

    ------------------------------
    Larry Simanek
    ------------------------------



  • 4.  RE: How Clearpass sets up authentication based on device type
    Best Answer

    EMPLOYEE
    Posted May 03, 2022 07:16 PM
    here is the screenshot for it.



    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------



  • 5.  RE: How Clearpass sets up authentication based on device type

    Posted May 05, 2022 01:01 PM
    We set up a role for our avaya voip phones. Then we created a role mapping (Authorization:[Endpoints Repository]:MAC Vendor  EQUALS  Avaya Inc). Then we created a wired mac auth policy that allowed the avaya voip phone and applied the "allow access" profile when a phone was plugged in. 

    This should give you a start

    ------------------------------
    Jason Tucker
    ------------------------------



  • 6.  RE: How Clearpass sets up authentication based on device type

    EMPLOYEE
    Posted May 06, 2022 07:05 PM
    thats the way to do it, also remember to use Endpoints: Conflict flag which indicates a change in the device category, in your enforcement policy.

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------