Security

last person joined: 2 days ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Policy Manager Profiling

This thread has been viewed 10 times
  • 1.  ClearPass Policy Manager Profiling

    Posted Oct 18, 2013 12:37 PM

    Hello. I have my controller arubaOS 6.1 and ClearPass Policy Manager 6.2 with Profiling. When user login in the ssid with 802.1x. ClearPass Profiling not device categorized. I have available dhcp fingerprinter in the controller?

     

    The controller device categorized ipad. Attachment imagen.

     

    Thanks



  • 2.  RE: ClearPass Policy Manager Profiling

    EMPLOYEE
    Posted Oct 18, 2013 12:43 PM

    Are you forwarding DHCP traffic of your clients to the ClearPass Policy Manager using a helper address?

     



  • 3.  RE: ClearPass Policy Manager Profiling

    Posted Oct 18, 2013 12:49 PM

    Not, as acive?



  • 4.  RE: ClearPass Policy Manager Profiling

    Posted Oct 18, 2013 12:52 PM

    Not, as active?



  • 5.  RE: ClearPass Policy Manager Profiling

    EMPLOYEE
    Posted Oct 18, 2013 12:54 PM
    You should add a helper address pointing to the ClearPass server(s) to each
    subnet where you would like profiling to occur.


  • 6.  RE: ClearPass Policy Manager Profiling

    Posted Oct 18, 2013 12:57 PM

    where this option is available?



  • 7.  RE: ClearPass Policy Manager Profiling
    Best Answer

    EMPLOYEE
    Posted Oct 18, 2013 01:00 PM

    You need to do it on the router interface (SVI / RVI) for the user subnet.

     

    In most deployments this is on an upstream device. 

     

        interface vlan 100

            ip helper-address <clearpass server>

     

     



  • 8.  RE: ClearPass Policy Manager Profiling

    Posted Oct 18, 2013 01:04 PM
      |   view attached

    Excellent. The option is correct.

     



  • 9.  RE: ClearPass Policy Manager Profiling

    Posted Oct 18, 2013 03:53 PM

    the ip helper-address what protocol our port use?.

     



  • 10.  RE: ClearPass Policy Manager Profiling

    EMPLOYEE
    Posted Oct 18, 2013 03:57 PM

    ClearPass reads the DHCP discover packet.

     

    [CLIENT]  UDP 0.0.0.0:68 -> 255.255.255.255:67 --> [ROUTER] UNICAST RELAY



  • 11.  RE: ClearPass Policy Manager Profiling

    Posted Oct 18, 2013 04:03 PM
      |   view attached

    I have the following issue.

     

    I have configuration service with authentication (domain controller), Authorization (Endpoint Repository),  Role(none),

     

    In the Enforcement attachment image.

     

    When one device login in the ssid 802.1x. In the Identity Endpoint not assigned Profiled. The alert in access tracker is Policy server Failed to get value for attributes=[OS Family].

     

     

     



  • 12.  RE: ClearPass Policy Manager Profiling

    EMPLOYEE
    Posted Oct 18, 2013 05:41 PM

    Can you please post  screenshot of the error?

     



  • 13.  RE: ClearPass Policy Manager Profiling

    Posted Oct 18, 2013 06:06 PM

    In the Endpoint database make sure that the device you are connecting from has the information available.

     

    That error might be indicating that the Endpoint profile for the device is missing the  [OS Family] attribute.

     

    The device profile might be blank and only has the MAC address.

     

    Aruba_EndpointDB_0001.png

     

    vs.

     

    Aruba_EndpointDB_0002.png

     

    If it is blank and you have an open SSID (for guests for example) that also has the dhcp help address configured try connecting to that SSID and then check the Endpoint profile again to see if it has all the information.

     

    Cheers