Security

 View Only
last person joined: 8 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass guest email address validation

This thread has been viewed 39 times
  • 1.  Clearpass guest email address validation

    Posted Oct 27, 2023 04:10 PM

    Hello  we would like to know if its possible to do this

    If a user types in his email, how can we validate its his real email?  guess  we could give them access for 5 mins to the internet but maybe that could be a little confusing to the client on how it works?  

    If we used a sms gateway using the phonenumber i guess it would be no issue, they would need to put the code that was send to their phonenumber but here i guess you need sms tokens and you have to pay for them.

    I could use social media login so then we can know who logged in but we would have to pick the correct ones that everyone could have.   My concern about this method would be apple users.  Some apple user that does not have google account neither uses microsoft account or have facebook account .  It would be really hard but could happen, and then he cant use the guest wifi

    There is anything for apple users? 

    In summary the scenario is " giving free access to anyone to the internet and that they can log in without the help of anyone or any sponsor but still we can know who log in the network , not random emails"

    If someone has a good idea for this scenario would be appreciated



  • 2.  RE: Clearpass guest email address validation

    Posted Oct 27, 2023 04:44 PM
    Honestly, consider single click Guest access.

    Many 10 minute or disposable email services out there, it would be more hassle than anything.

    My .02...





  • 3.  RE: Clearpass guest email address validation

    Posted Oct 27, 2023 05:49 PM

    But we need to get the information of who is connecting, thats why the single click guest accesss  does not work for us

    There is nothing for Apple? as a source to log in the guest wifi?

    For androids i could use gmails accounts but for apples? i have nothing because their ID is associated to an email that it could not be gmail

    There must be a way, clearpass always can :)




  • 4.  RE: Clearpass guest email address validation

    MVP
    Posted Oct 30, 2023 08:07 AM

    If you are also using Aruba wireless. one other consideration that we use would be to create your own guest prtal page on a web server and ise the ClearPass REST API and the AOS captive portal profile for Guest Access.

    Although we are not doing this, you should nbe able to validate the email address before submitting to ClearPass.

    Doing this gives great flexibility. We are currently using a php server to do this for self-registration (redirecting @liberty.edu to our secure onboarding), sponsored guest account creation, & sponsored guest login. We make use of the ClearPass Guest print templates to be able to verify the sponsored guest password before submitting to ClearPass. We are also doinh MAC caching in ClearPass for guest logins.

    Let me know if you wish more details. 



    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------



  • 5.  RE: Clearpass guest email address validation

    Posted Oct 31, 2023 05:29 AM

    We use CP to have the guest self-sponsor their access using 10 mins timer for them to get to their inbox (any inbox) and click to approve their own access for 24 hours.
    It works well, folks don't struggle with it. If the link in the email isn't clicked within 10 mins their access drops back to 'guest logon' and all they can access is CP.



    ------------------------------
    Nathan
    ------------------------------



  • 6.  RE: Clearpass guest email address validation

    Posted 5 days ago

    Hello Nathan,

    Do you have any document for these workaround ?. My company is looking for the same solution. if you have any doc, please share.




  • 7.  RE: Clearpass guest email address validation

    MVP
    Posted Oct 31, 2023 04:00 PM
    Using emails is missleading when it comes to having to verify who the user is.

    Everyone can open a fake email address and register.

    We had similar requirements and integrated it with SMS Gateway.

    Initially you have to register using a mobile phone number. Clearpass generates a password and sends it to this mobile Phone number.
    Then you type username and password received via SMS and there you gi.

    Phone numbers are easy to be verified as in most countries when getting a SIM Card or eSIM you have to provide informations relates to your identity.
    In case of any missleading situtation, you can track down the user based on the mobile phone number.



    ---------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP |
    -Just an Aruba enthusiast and contributor by cases-
    ---------------------------------





  • 8.  RE: Clearpass guest email address validation

    Posted Nov 02, 2023 03:08 PM

    The problem here is that i guess integrating it with sms will cost money.  The client was looking for something free if it was possible 

    Guess we will use many social media options to get in the network 




  • 9.  RE: Clearpass guest email address validation

    EMPLOYEE
    Posted Nov 03, 2023 11:36 AM

    If your network is managed by Central, you could consider Cloud Guest as part of Central. That includes the SMS services.

    Also, it my depend a bit on where you live, but SMS services can be quite affordable with a few cents (EUR/USD) per message. In most cases that is not your budget killer.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------