Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass 6.6.7 not sending timeout value to Palo Alto

This thread has been viewed 1 times
  • 1.  ClearPass 6.6.7 not sending timeout value to Palo Alto

    Posted Sep 19, 2017 04:55 AM

    One of the changes in ClearPass 6.6.7 was to send a timeout value of 0 to Palo Alto firewalls to ensure that IP-user-mappings does not expire. We upgraded to 6.6.7 a few weeks ago, but we cannot see any change in the behaviour. When I check the XMP-API entries in our Palo Alto firewall I still see a timeout value of 2700 seconds (default value on the Palo Alto), and I see no timeout value being sent in the postauthctrl log files. We are running PAN-OS version 7.1.10. However, when we check with our VAR who have the same setup as us except they run PAN-OS version 8, they see timeout values being sent from their ClearPass.

     

    Their postauthctrl entries look like this:

     

    <entry name="username" ip="10.x.x.x" timeout="0"/>

     

    Ours look like this:

     

    <entry name="username" ip="10.x.x.x"/>

     

    In the relase notes for 6.6.7 it says that the timeout value change is for PAN-OS version 7.1.5+

     

    Has anyone else seen this? I have opened a TAC case.



  • 2.  RE: ClearPass 6.6.7 not sending timeout value to Palo Alto

    Posted Sep 19, 2017 11:45 AM

    I'm seeing the same thing you are, I don't see a timeout value being sent (from the CPPM logs). Let us know what TAC says. 

     

    However, our PAN updates seem to have completely broken right now, we upgraded our Panorama to 8.0.4 last week, and now our CPPM updates don't seem to be getting to the firewalls (which are still on 7.1.x). We send updates to Panorama, not directly to the firewalls. I have a case open with PAN to see if it's on their side.



  • 3.  RE: ClearPass 6.6.7 not sending timeout value to Palo Alto

    Posted Sep 19, 2017 03:30 PM


  • 4.  RE: ClearPass 6.6.7 not sending timeout value to Palo Alto

    Posted Sep 20, 2017 03:04 AM

    Reply from TAC is that has been filed as a bug. I am waiting for the defect number.



  • 5.  RE: ClearPass 6.6.7 not sending timeout value to Palo Alto

    Posted Sep 25, 2017 04:16 AM

    Bug number is 42300



  • 6.  RE: ClearPass 6.6.7 not sending timeout value to Palo Alto

    Posted Nov 01, 2017 03:36 AM

    TAC has now told me that is is confirmed as a bug and will be fixed in ClearPass version 6.7 which is scheduled for release in December.