Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
Evil Twin Detection with OnGuard
Policy Manager OnGuard Agent supports Evil Twin Detection for Wired Interfaces.
Introduction
To enable OnGuard Agent to check for the presence of an "evil twin" with Wired interface, a new option,, has been added to the Agent Enforcement Profile attributes (for details, see Agent Enforcement Profile). When OnGuard Agent detects an Evil Twin for Wired interface, it sends a WebAuth request with the Host:EvilTwin attribute having the value "MayExist,” indicating that an Evil Twin may exist. The Host:EvilTwin attribute is available in Service rules, Role Mapping, and Enforcement profiles. Admins can use this attribute to take action by applying Policy Manager enforcement profiles.
|
|
This feature is supported only with wired interfaces; it is not available for wireless interfaces. Additionally, this feature is only supported with a network hub, not an unmanaged switch. |
Configuring Evil Twin Detection for Agent Enforcement Profile
Policy Manager administrators can use the Host:EvilTwin attribute to apply other enforcement profiles to send email, issue a disconnect request, update endpoint attributes, and/or send updates to third-party firewalls Firewall is a network security system used for preventing unauthorized access to or from a private network..
To enable the Evil Twin Detection attribute for an Agent Enforcement profile:
1. Navigate to > > .
The page opens.
2. Click .
The > tab opens.
3. From the drop-down, select .
The > dialog opens.
4. Specify the tab parameters as described in Agent Enforcement Profile.
5. Select the tab.
6. Add the Enable Evil Twin Detection attribute as shown in Figure 1:
Figure 1 Agent Enforcement Profile > Attributes Tab
7. Click .
Configuring Evil Twin Detection for Enforcement Policy
To configure an enforcement policy with the Host:EvilTwin condition:
1. Navigate to Configuration > Enforcement > Enforcement Policies.
The page opens:
2. Click Add.
The Add Enforcement Policy page opens to the tab.
3. Specify the > tab parameters as described in Configuring Enforcement Policies.
4. In the Rules tab, click Add Rule to display the Rules Editor.
5. Configure the Host:EvilTwin EQUALS MayExist condition as shown in Figure 2:
Figure 2 Configuring Enforcement Policy with Evil Twin May Exist Condition
6. Click .
Evil Twin OnGuard WebAuth Request Attribute in Access Tracker
The tab shows protocol-specific attributes that Policy Manager received in a transaction request, including authentication and posture details (if available). The tab also shows computed attributes that Policy Manager derived from the request attributes. All of these attributes can be used in role-mapping rules.
Access Tracker records the presence of the Host:EvilTwin attribute on the > page.
1. Navigate to > .
2. From the page, select the pertinent WebAuth session.
The page opens.
3. Click the tab and select the section.
The Host:EvilTwin attribute is displayed as shown in Figure 3.
Figure 3 Host:EvilTwin Attribute Displayed in Access Tracker > Request Details