Security

last person joined: 15 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass - Disabling Automatic Updating

This thread has been viewed 3 times
  • 1.  ClearPass - Disabling Automatic Updating

    MVP
    Posted Oct 11, 2017 12:57 PM

    Good afternoon all,

     

    With the recent issue with the AV update that crashed multiple clearpass servers, I would like to ensure the AV/Posture updates are not automatically downloaded by ClearPass, so I can apply them in test environments prior to production. How would I go about that? I know there is an option in Cluster-Wide Parameters, but I don't know if that's for the right updates.

     

    Thanks.



  • 2.  RE: ClearPass - Disabling Automatic Updating



  • 3.  RE: ClearPass - Disabling Automatic Updating

    MVP
    Posted Oct 11, 2017 02:26 PM

    @Cappalli thank you for the information. I'll take that option into account, but do we know the option in Cluster-Wide Parameters - does that include AV/Posture and Firmware updates? I looked up the description in the User Guide and it isn't specific.

     

    Thanks.



  • 4.  RE: ClearPass - Disabling Automatic Updating

    Posted Oct 11, 2017 01:31 PM

    Curious on this, too. We've identified three approaches:

    1. Remove subscription ID.
    2. Toggle Cluster-wide parameter
    3. Block via some other means. Proxy, content filter, etc.

    The one you've suggested (#2) seems like it will produce the least amount of red scary text on the Updates page. Hoping that someone from Aruba can chime in.



  • 5.  RE: ClearPass - Disabling Automatic Updating

    MVP
    Posted Oct 11, 2017 02:28 PM

    @mcdaviddj I agree with those three approaches. I'm hoping #2 also solves the same problem, but I also need verification to be sure.

     

    The other easiest option is #1, as some places have different teams who manage resources, and #3 could take some time to get done and undone.



  • 6.  RE: ClearPass - Disabling Automatic Updating

    EMPLOYEE
    Posted Oct 12, 2017 05:05 AM

    In Service Parameters --> Clearpass System Services you could put a dummy proxy address in there.

     

    You could also put a fake DNS entry on your DNS server for clearpass.arubanetworks.com.

     

    Neither of these are elegant though.



  • 7.  RE: ClearPass - Disabling Automatic Updating

    EMPLOYEE
    Posted Oct 11, 2017 06:57 PM

    Option 2 is only for software updates.