Security

 View Only
  • 1.  Need help setting up Mac spoofing prevention.

    Posted May 23, 2025 10:49 AM

    Hello,

    i am trying to prevent mac spoofing using the conflict feature in Clearpass, but i either make it block every connection or allow all.

    Can anyone please give me an example of how to configure it

    Thanks

    Here is the config that i configured, but now even legitimate mac authentication from the same device as before are being blocked



  • 2.  RE: Need help setting up Mac spoofing prevention.

    Posted May 25, 2025 07:09 PM

    you can use the Conflict attribute and put the devices in a "conflict-role" as you are doing but put them on a VLAN  with limited access so you can investigate them.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: Need help setting up Mac spoofing prevention.

    Posted May 26, 2025 10:18 AM

    You can't assign the Conflict-Role as default role in the role mapping policy.

    With this condition you states that if Conflict=True assign the role Conflict-Role, if not true assign the Conflict-Role.

    To solve this you have to change the default role to something else, maybe [Other].



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 4.  RE: Need help setting up Mac spoofing prevention.

    Posted May 26, 2025 10:25 AM

    Thanks Jonas, i did noticed and change it just after i post this thread, i have other question please, how can i profile devices other than DHCP, one of our customers for some reason deoes not have DHCP, so we cant rely on DHCP fingerprints for profiling, is there any other way to profile devices ?




  • 5.  RE: Need help setting up Mac spoofing prevention.

    Posted May 26, 2025 10:37 AM

    Yes, there are a number of other technics for profiling devices. This, rater old but still valid, document describes them:

    https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100323en_us

    In general DHCP is the easiest way to implement and what I have been using in almost every case.

    If you have integration with Intune you can benefit from the information in the Intune database as well. 



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 6.  RE: Need help setting up Mac spoofing prevention.

    Posted May 27, 2025 08:46 AM

    Use an external SPAN-based profiling tool. Like Ordr, Medigate, etc. Aruba Central managed switches also offer native profiling that integrates with ClearPass.