Security

 View Only
  • 1.  Port Security with clearpass

    Posted Jun 14, 2026 07:21 PM

    Hey All 

    I have Aruba switch 2930 and ClearPass, I am trying to setup port security with device profiling so I can do mac authentication and user authentication, I have got the user side for devices to work, but I am not able to get the mac authentication to work or the profiling of devices like IP Phone to work on any port that it is plugged into. I am also trying to do the mac authentication with out maintaining a static mac list. 

    Any help would be great,

    Thanks in advance



  • 2.  RE: Port Security with clearpass

    Posted Jun 17, 2026 06:31 AM

    The profiling and authentication is done in multiple steps, all handled in the MAC authentication service you configure in ClearPass.

    For profiling to work the MAC authentication service must be configured with the authentication method [Allow All MAC Auth] and the checkbox Profile Endpoints enabled.

    In the Profiler tab, make the following selections:

    This is the steps a new device will go through for profiling and authentication

    1. When a new device connects, you allow the device to connect. Assign a role "Unknown Device" or "Not profiled" or any other meaningful name. Assign either a specific VLAN or a role with limitation to only send DHCP requests to ClearPass. IP Helper pointing to ClearPass must be configured on the VLAN.
    2. Device is allowed on the network and sends the DHCP request ClearPass will perform the profiling.
    3. After the device has been profiled ClearPass will send a Dynamic Authorization (CoA) to get the client to authenticate one more time.
      This require the Dynamic Authorization checkbox to be enabled in the Network Device configuration as well as the port open and the Dynamic Authorization configuration done on the switch side.
    4. Second authentication will take place, now as a profiled device. In this phase ClearPass can utilize the profiling information and assign role and enforcement based on this information
    5. Each time the device renew the DHCP lease the profiling information is updated. If the device change behavior you can create a rule to block devices with a profiling conflict

    Do not use static host lists, they are a only in ClearPass for backward combability. I would recommend using Guest Device Repository to store MAC addresses and assign roles if you have devices that have fixed IP addresses that are not profiled or specific devices where profiling isn't applicable for some reason.

    Even though it's called Guest device repository, you can use it for other types of devices. You can also create operator profiles for users or teams needing to maintain specific device types.

    Check the document ClearPass Solution Guide Wired Policy Enforcement for more details on switch configuration.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------