Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Enforcement Policy Guest Device Repository

This thread has been viewed 4 times
  • 1.  ClearPass Enforcement Policy Guest Device Repository

    Posted Jul 26, 2017 10:43 AM

    I'm trying to leverage the a policy that uses Authorization:[Guest Device Repository]. There are three name options for said type, AccountStatus, RemainingExpiration, and Sponsor. AccountStatus. I was hoping to use AccountStatus but I'm not sure what values it contains for active/disabled so I've only been able to use "Exists" but I want to be more implicit. Can someone tell me the options or how I can get into the database backend to check the values?

     

    Thanks,

     

    Rosie



  • 2.  RE: ClearPass Enforcement Policy Guest Device Repository
    Best Answer

    EMPLOYEE
    Posted Jul 26, 2017 10:48 AM
    225 = disabled
    226 = expired
    0 = enabled and valid


  • 3.  RE: ClearPass Enforcement Policy Guest Device Repository

    Posted Jul 26, 2017 11:21 AM

    As always, thank you for the quick reply Tim. Is that status of the account or of the device? I disabled the device and it is sitll receiving a 0 for accountstatus. I am assuming I asked the wrong question at this point.



  • 4.  RE: ClearPass Enforcement Policy Guest Device Repository

    EMPLOYEE
    Posted Jul 26, 2017 11:23 AM
    The device account. Guest Device Repository is used for device registration (headless, IoT, traditional MAC address registration, etc)


  • 5.  RE: ClearPass Enforcement Policy Guest Device Repository

    Posted Jul 26, 2017 11:26 AM

    I must just be impatient. Do you know how long it takes for a disabled device to "register" with the enforcement policies? It is behaving as expected now.



  • 6.  RE: ClearPass Enforcement Policy Guest Device Repository

    EMPLOYEE
    Posted Jul 26, 2017 11:30 AM
    It may have been cached.


  • 7.  RE: ClearPass Enforcement Policy Guest Device Repository

    Posted Apr 02, 2019 04:57 PM
      |   view attached

    Tim, 

     

    I have a ClearPass Lab environment running CPPM version 6.7.9.109195.

     

    I am working through your "Wired Policy Enforcement Solution Guide" and I am stuck in the MAC Authentication Enforcement Policy section of the guide (Page 28). When trying to create the 5th condition, "Authorization: [Guest Device Repository]:Device Account Enabled EQUALS (true), "Device Account Enabled " is not an option in the dropdown menu.

     

    I have attached my Enforcement Policy for comparison. Just wanting to verify that my 5th condition is configured correctly. Thanks.