Aruba Apps

 View Only
last person joined: 7 days ago 

The HPE Aruba Networking Apps board is designed to address questions, comments, and feature requests for all HPE Aruba Networking mobile Apps
Expand all | Collapse all

clearpass policy to block devices using wrong policy

This thread has been viewed 14 times
  • 1.  clearpass policy to block devices using wrong policy

    Posted Aug 31, 2023 03:06 PM

    Hi, I was wondering if there is a way to have clearpass block or remove devices that don't match a policy?  I work on a college campus and we have student self register their gaming and streaming devices, but for there computers they need to configure 802.1x, some students will register their computers' as gaming devices, currently we manually go through the mac address's in managed devices,  is it possible for clearpass to determine that this isnt a xbox or PSx or Nintendo and then disable the mac for access?

    Thank you

    Pino  



    ------------------------------
    Peppino Muraca
    Manager of Network Services
    Stonehill College
    W:508-565-1193
    pmuraca@stonehill.edu
    ------------------------------


  • 2.  RE: clearpass policy to block devices using wrong policy

    EMPLOYEE
    Posted Sep 02, 2023 10:59 AM

    In general, the list of policies in Clearpass determine what role a device will be tagged with (role policies) and in enforcement, what enforcement profile will be sent back.  If a device does not satisfy any of those policies, a device is either tagged with the default role or default enforcement policy.

    I hope I am answering your question...



    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    HPE Design and Deploy Guides: https://community.arubanetworks.com/support/migrated-knowledge-base?attachments=&communitykey=dcc83c62-1a3a-4dd8-94dc-92968ea6fff1&pageindex=0&pagesize=12&search=&sort=most_recent&viewtype=card
    ------------------------------



  • 3.  RE: clearpass policy to block devices using wrong policy

    MVP
    Posted Sep 04, 2023 03:50 AM

    In such cases you should be using Device Profiling . 
    Another way could be to register devices under a Group and then TAG the Role to that group.

    You would have to go to Configuration > Identity > Endpoints

    Then when you register (or edit) the XBOX, you go to the Attributes TAB. On Attribute you can choose: Device Type with Value: Game Console

    Then when you do the service, you can tag on the role mapping:
    Type: Device
    Name: Device Type
    Operator: Equal
    Value: Game Console

    And then  you assign a role name whichever you are using.



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP |
    -Just an Aruba enthusiast and contributor by cases-
    ------------------------------