Wireless Access

 View Only
  • 1.  Prevent Users to Access many devices

    Posted Mar 02, 2026 06:54 AM

    Hi Dears, hope everyone is good.

    We have Aruba Central integrated with CPPM, and the customer wants the user to have access to 1 device, no more devices.

    and already using the Active Directory for some users and CPPM'S internal DB too.

    Need a solution for this, please.
    Thanks in advance



    -------------------------------------------


  • 2.  RE: Prevent Users to Access many devices

    Posted Mar 02, 2026 09:33 AM

    any response please

    -------------------------------------------



  • 3.  RE: Prevent Users to Access many devices

    Posted Mar 02, 2026 10:36 AM

    Based on this description, it's not clear to me what you try to achieve. Is devices access points, switches? Or is it end user clients?

    What type of network equipment do you have?

    How does your current configuration on Central and ClearPass look like?

    The generic answer is: write the right policy matching your requirements. It may be best to work with your HPE Networking partner to get configured once it's clear what you want to do. If you don't have the experience with ClearPass, it may be a hard task to perform.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 4.  RE: Prevent Users to Access many devices

    Posted Mar 02, 2026 10:56 AM

    Hi Herman, thank you for your response.

    I meant that the customer wants the end user, when connecting to the wireless, just use 1 device with their credentials and cannot connect from other devices, and every user in the network is allowed to connect through 1 device (mobile/tablet/ wireless laptop), no more.

    We integrate with Aruba Central as we configured SSIDs and services on CPPM for Wireless.

    -------------------------------------------



  • 5.  RE: Prevent Users to Access many devices

    Posted Mar 02, 2026 11:14 AM

    How conversant with ClearPass are you?

    You'd need to configure a concurrent device limit check in ClearPass.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 6.  RE: Prevent Users to Access many devices

    Posted Mar 02, 2026 05:08 PM

    I have a good knowledge of how configure services, policies, and profiles.

    The customer wants to limit the number of devices a single user can use on the wireless network.

    I know that if we need to control the device limitition we need an onboard license, and we now only have Access.

    -------------------------------------------



  • 7.  RE: Prevent Users to Access many devices

    Posted Mar 02, 2026 05:37 PM

    Has nothing to do with Onboard licenses.

    https://airheads.hpe.com/discussion/how-to-configure-8021x-with-ad-authentication-and-per-user-device-limits-in-aruba-cppm#bm26ebf56e-471b-4b4c-8fca-faf6ffb2eb27

    https://airheads.hpe.com/discussion/clearpass-active-session-restriction#bmd6435b5b-d99e-4418-9c5e-b91209c9af04



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 8.  RE: Prevent Users to Access many devices

    Posted Mar 03, 2026 03:56 AM

    Should the user always use a specific device? Then you can save the username in the endpoint and evaluate the attribute Authorization:[Endpoints Repository]:Unique-Device-Count. This approach is easier, but it doesn't work if the end devices use private MAC addresses.

    An alternative approach is to use the Active Sessions Counter from the [Insight Repository] Authentication Source. This allows you to ensure that the user only goes online from one device at a time. Carson describes this approach in his posts.



    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACX - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------