Hi Ariyap,
Aruba MPSK works together with Aruba ClearPass.
- The Aruba controller does a mac-authentication to ClearPass (not the client).
- ClearPass lookup for the client mac-address in the Guest Module under Devices
- In the Guest Module each client mac-address have his own PSK and Role assigned in the Device database.
- ClearPass answer with a RADIUS packet to the controller to instruct which PSK must be allowed for this mac address.
- ClearPass answer with a RADIUS packet to the controller to instruct which VLAN the client must be placed in (based on his role and policy decision).
I think the mac-address can be spoofed but you always need to known the PSK bound to this mac-address, thats unique. And aslong the mac-address and PSK are used to gether you always get back the same PSK, Role and VLAN in the RADIUS response to the controller.
Back to the authentication phases on the controller:
1. 802.11 association
2. 802.11 authentication
3. MPSK Process
4. PSK exchange / 4-way handshake
5. Assign Vlan/Role
6. Layer 3 DHCP Request
The way how dynamic vlans itself works are safe, the RADIUS traffic happens between Controller and ClearPass in the management VLAN (not vissible to the client). ClearPass instruct the controller to which VLAN must be used to the client, based on the ClearPass policy. When the management VLAN is untrusted you can also use RADSEC to encapsulate and encrypt the RADIUS traffic.
MPSK is most often used for IOT devices (devices that don't support 802.1x for example older printer, camera's, etc. It's in my opinion less suitable for guest or byod devices because you have to register each mac-address in the database and can easy overwhelm your Servicedesk. For BYOD like devices, Aruba ClearPass Onboard is more suitable where unmanaged clients can use EAP-TLS (certificate) based authentication, which is the holy grail / most secure authentication method we known those days.
------------------------------
Marcel Koedijk | MVP Guru 2021 | ACEP | ACMP | ACCP | ACDP | Ekahau ECSE | Not an HPE Employee | Opinions are my own
------------------------------
Original Message:
Sent: Jan 05, 2022 06:31 PM
From: Ariya Parsamanesh
Subject: How safe are dynamic VLANs on the same SSID
with MPSK you can have the ioT/users in different VLANs and then apply various access policies based on the user-role
Check this tutorial on AOS10 and MPSK.
https://community.arubanetworks.com/community-home/digestviewer/viewthread?GroupId=7&MessageKey=52a23f14-0303-4615-b3ab-3bd0b65f225e
------------------------------
Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
------------------------------