Security

 View Only
last person joined: 7 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Mac Auth for Wireless SSID on Aruba IAPs

This thread has been viewed 19 times
  • 1.  ClearPass Mac Auth for Wireless SSID on Aruba IAPs

    Posted 5 days ago

    A new customer has ClearPass and Aruba IAPs managed by Aruba Central.

    They have a requirement for a new Wireless SSID that only permits certain devices to join if their mac address is on a whitelist of sorts.

    I have created a new Wireless SSID in Aruba Central with the following

    + Mac Authentication enabled

    + Called Station ID Type: MAC Address

    + Pointed to the ClearPass servers 

    How would I go about setting up a Mac Authentication service in ClearPass? I checked the Endpoints Repository and the required devices are already registered there. I'm assuming this can be used as the authentication source, then an additional condition/rule/policy that specifies the mac addresses allowed?



  • 2.  RE: ClearPass Mac Auth for Wireless SSID on Aruba IAPs

    MVP GURU
    Posted 5 days ago

    You can use a number of sources for MAC Authentication. You could register the devices via the web portal in Guest known as "Device Registration", and then use the Guest Device Database as your Authentication/Authorization source. The endpoint database can also be used if you want to grab fingerprinted data like OS type or vendor if the device gets profiled. You can also use a static host list to authenticate against.



    ------------------------------
    Dustin Burns

    Lead Mobility Engineer @Worldcom Exchange, Inc.

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2022-2023
    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 3.  RE: ClearPass Mac Auth for Wireless SSID on Aruba IAPs

    Posted 5 days ago

    If using the Guest Device Database or Endpoint Database as the MAC authentication source. Then how would you specify that only certain devices can join the Wireless SSID?




  • 4.  RE: ClearPass Mac Auth for Wireless SSID on Aruba IAPs

    EMPLOYEE
    Posted 5 days ago

    the key is to add an attribute to the endpoint db and then either manually or using a workflow assign a value to the new attribute.

    And finally during the authorisation check to the existence of that attribute and allow/deny access.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------