This is the way you want to do it, each user can only see things registered to 
them. You’ll need clearpass guest for this.

Once it’s up and running, people love it, and it’s easy to manage. We’ve even 
set up a highly restricted account for student helpdesk to be able to update 
device fingerprints to help out, but that’s all they can see or do.

Clearpass is an amazing , flexible platform. You won’t regret going with it.


[The Culinary Institute of America]
Robert Harris
Manager – Telecom, Networks, & AV Services
Culinary Institute of America
1946 Campus Drive
Hyde Park, NY
845-451-1681
www.ciachef.edu<http://www.ciachef.edu/>
Food is Life
Create and Savor Yours.™

Please consider the environment before printing this e-mail.



From: The EDUCAUSE Wireless Issues Community Group Listserv 
<[email protected]> On Behalf Of Michael Davis
Sent: Wednesday, March 4, 2020 10:32 AM
To: [email protected]
Subject: Re: [WIRELESS-LAN] Device visibility in Aruba AirGroup + ClearPass

If you setup your SSIDs not to allow client-to-client communication and pass
all mDNS,etc. traffic through CPPM, then the users can register devices and
only those they designate to share to (clients, APs, ap-groups, etc.) can see
the device.

Our primary SSID (eduroam) has a username@domain that users can share
mDNS devices to and any authenticated devices on eduroam can access
the mDNS device.

On 3/4/20 10:19 AM, Craig D Rice wrote:
We are an Aruba shop and are evaluating AirGroup + ClearPass to provide 
students a more home-like experience in their residence halls. That is, we 
would like students to be able to register and see only their registered 
devices.

If a user registers a device in ClearPass, is that device visible to 
non-registered devices (or devices registered to another user) -- even if the 
devices are associated with the same AP?

We have received conflicting answers from our Aruba SEs, account exec, and TAC, 
so we are hoping to learn how to limit device visibility from others who are 
using ClearPass.

Thanks for your advice!
Craig
--

Craig D. Rice
Director of Enterprise Infrastructure | IT
[St. Olaf College]
Office: +1-507-786-3631
1510 St. Olaf Avenue Northfield, MN 55057-1097  USA
stolaf.edu
<http://stolaf.edu/>


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community




--

 Mike Davis

 IT - University of Delaware  - 302.831.8756

 Newark, DE  19716         Email [email protected]<mailto:[email protected]>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

Reply via email to