Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Profiler Inquiry?

This thread has been viewed 1 times
  • 1.  Clearpass Profiler Inquiry?

    Posted Sep 12, 2015 11:34 AM

    I'm using HP wired Switch 802.1x and I see endpoints profiler is not profiled so I wanted to know what may be the problem I want to know if thsi configurations is right ,also what is the right enforcment should be done ?

     

    Role name :Unknown Device

    Role-Mapping
    (Authorization:[Endpoints Repository]:Category  NOT_EXISTS   )     Unknown Device

     

    Endorcment Policy

    tips role equals [user auuthenticated]
    tips role equals 802.1x authentication
    tips role equals unknow device

     

     

     

     

     

     



  • 2.  RE: Clearpass Profiler Inquiry?

    EMPLOYEE
    Posted Sep 12, 2015 11:36 AM
    Do you have helper addresses configured on the L3s?


    Thanks,
    Tim


  • 3.  RE: Clearpass Profiler Inquiry?

    Posted Sep 12, 2015 11:55 AM

    so you said that I have do IP helper address pointing to clearpass IP on the Interface VLAN?



  • 4.  RE: Clearpass Profiler Inquiry?
    Best Answer

    EMPLOYEE
    Posted Sep 12, 2015 11:58 AM
    Yes. Whichever interface is the client's DG, should have a helper address. Sometimes this is upstream of the edge switch..


    Thanks,
    Tim


  • 5.  RE: Clearpass Profiler Inquiry?

    Posted Sep 12, 2015 12:05 PM

    One more thing Mr tim what VLAN Enforcment should be the Action for the unknown device?



  • 6.  RE: Clearpass Profiler Inquiry?
    Best Answer

    EMPLOYEE
    Posted Sep 12, 2015 12:08 PM
    You would want to return a dynamic ACL that only allows DHCP.


    Thanks,
    Tim


  • 7.  RE: Clearpass Profiler Inquiry?

    Posted Sep 12, 2015 12:13 PM

    so for HP Switch what type of enforcment type can do this?



  • 8.  RE: Clearpass Profiler Inquiry?
    Best Answer



  • 9.  RE: Clearpass Profiler Inquiry?

    Posted Sep 12, 2015 07:33 PM

    damm, these TechNotes are pretty useful, shame that guy that wrote then never gets any Kudos...!!!!!......LO(very)L......