Security

Reply
Super Contributor I
Posts: 324
Registered: ‎05-09-2013

ClearPass Time Source Now Minus 3 Days

Good morning everyone,

 

I configured ClearPass to integrate with an existing AirWatch solution. I tried configuring a condition in Role Mapping that would verify the device had checked in to AirWatch in the past 3 days from that authentication.


I went to Time Source and copied the "now_plus_1day" attribute and modified it as follows:

 

Now Plus 1 Day

SELECT (EXTRACT (EPOCH FROM NOW() + interval '1 days'))::int AS now_plus_1day;

 

Now Minus 3 Days

SELECT (EXTRACT (EPOCH FROM NOW() - interval '3 days'))::int AS now_minus_3days;

 

I also updated the Name and Alias to match. I left the Data Type as Integer. 

 

When an authentication comes through, the access tracker logs show the entry as a string of numbers and not a date/time stamp. The Last Checked In for AirWatch in the logs is a date/time stamp. Due to this it is not interpreting it the way it should and we are getting an "out of compliance" role instead of "airwatch-valid" role. 

 

Any recommendations or anything I missed to accomplish this? Would anyone have a working example?

 

Thank you.

 

Michael Haring | Network Engineer - ACMP, ACCP
Comm Solutions Company | www.commsolutions.com
Guru Elite
Posts: 8,050
Registered: ‎09-08-2010

Re: ClearPass Time Source Now Minus 3 Days

[ Edited ]

It's likely due to the format of the timestamp.

 

Try this instead:

 

SQL query:

select localtimestamp(0)+ interval '3 days' as three_days_from_now

Then create the attribute to match.

mharing-3daysfromnow.PNG


Tim Cappalli | Aruba ClearPass TME
@timcappalli | ACMX #367 / ACCX #480 / ACEAP / CWSP
Super Contributor I
Posts: 324
Registered: ‎05-09-2013

Re: ClearPass Time Source Now Minus 3 Days

Thanks I will give that a try, would the minus symbol work to incorporate "3 days ago" instead of "3 days from now"? 

Michael Haring | Network Engineer - ACMP, ACCP
Comm Solutions Company | www.commsolutions.com
Super Contributor I
Posts: 324
Registered: ‎05-09-2013

Re: ClearPass Time Source Now Minus 3 Days

Tested the string you provided, and it worked perfectly. Thank you for your help!

Michael Haring | Network Engineer - ACMP, ACCP
Comm Solutions Company | www.commsolutions.com
Search Airheads
Showing results for 
Search instead for 
Did you mean: