Security

 View Only
last person joined: 18 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

MPSK recommendation

This thread has been viewed 37 times
  • 1.  MPSK recommendation

    Posted Oct 17, 2022 08:47 AM
    hello 
    i m thinking to implement MPSK feature for wireless healthcare devices in order to increase the security of it..
    so do you recommend to use this feature ? or i will face problems later ? 
    also do you recommend to apply a password for each device or  1 password for each vendor or group of devices ?
    is it will be too much headache  in operation if i make password for each device ??

    hope to hear some opinion


  • 2.  RE: MPSK recommendation

    Posted Oct 17, 2022 08:49 AM
    I think its a great solution and works really well.  The answer to unique password per device or per group is a "it depends" on the environments security vs manageability.  Check out this blog post I did recently on this exact topic: https://www.adamhollifield.com/2022/09/clearpass-mpsk-per-device-type-with.html


  • 3.  RE: MPSK recommendation

    Posted Mar 21, 2024 12:47 PM

    I am tring the config described in the https://www.adamhollifield.com/2022/09/clearpass-mpsk-per-device-type-with.html  but I can see the devices not are not profiling, he remain not profiled and I can't use the attributes for authorize the devices,

    have you any suggest?



    ------------------------------
    ACMP ACSP ACCP ACEP
    ------------------------------



  • 4.  RE: MPSK recommendation

    Posted Mar 21, 2024 01:10 PM

    Looks like you don't have profiling data coming into ClearPass.  What probes are you using?  Do you have DHCP relay configured?




  • 5.  RE: MPSK recommendation

    Posted Mar 22, 2024 03:04 AM
    Dhcp relay is configured in the management interface of wifi controller and in the core switch vlan profiling.
    But my doubdt is: how the client can send the dhcp request before receiving the psk key.

    Dario Nardello

    La informiamo che il trattamento dei dati sarà effettuato in conformità al Regolamento UE 2016/679 (GDPR), con modalità funzionali alle finalità del trattamento stesso. La nostra Informativa Privacy è consultabile al link: https://www.axians.it/documenti_axians_italia/. We kindly inform you that data will be processed in compliance with the provisions of EU Regulation 2016/679 (GDPR), with methods functional to the purposes of the. Our Privacy Policy is available at: https://www.axians.it/documenti_axians_italia/

    CONFIDENZIALE: Le informazioni contenute nella presente comunicazione ed i relativi allegati sono confidenziali, riservati e destinati esclusivamente al destinatario sopra indicato il quale è l'unico soggetto autorizzato ad usarli, copiarli e, sotto la propria responsabilità, diffonderli. Se avete ricevuto questo messaggio per errore, vi preghiamo di distruggerlo e di informarmi immediatamente all'indirizzo email indicato. Ai sensi del Regolamento generale sulla Protezione dei Dati Personali UE 2016/679 e dell'art. 616 cod. pen. è proibita qualsiasi forma di riproduzione o divulgazione del documento trasmesso senza l'eplicito consenso del mittente del documento. CONFINDENTIAL: The information contained in this communication and its attachments are confidential and are intended exclusively for the recipient who is the only person authorized to use it, copy it and, under his own responsibility, spread it. If you have received this message in error, please destroy it and reply to me immediately. Pursuant to the Regulation EU 2016/679 of the European Parliament and of the Council on data protecion and art. 616 of Italian Penal Code any form of reproduction or disclosure of the transmitted document is prohibited without the explicit consent of the sender of the document.





  • 6.  RE: MPSK recommendation

    Posted Mar 22, 2024 09:31 AM
    It doesn’t, that’s why the MPSK policies are structured the way they are. This flow heavily relies on CoA so once a DHCP is packet is received the endpoint is re-evaluated and if it no longer matches the configured profiling data it is removed from the network. The connecting device has network access up until the DHCP packet is received by ClearPass.




  • 7.  RE: MPSK recommendation

    Posted Mar 22, 2024 01:38 PM

    thank you  ahollifield

    I followed your document, but was not working, Discovered a mistyping in the coa device in clearpass.

    it seem now working only tested with 2 devices.



    ------------------------------
    ACMP ACSP ACCP ACEP ACDP
    ------------------------------



  • 8.  RE: MPSK recommendation

    Posted Oct 17, 2022 03:19 PM
    We use MPSK feature for healthcare devices too. We have different password for each device. Previously we did a PSK SSID but it was very difficult to figure out what all the connecting devices were, so even if it takes a bit more time to connect the devices to network you can actually figure out what you have in the network and makes life easier later on