Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass / Soti Integration (MDM Enabled Endpoint tag)

This thread has been viewed 2 times
  • 1.  Clearpass / Soti Integration (MDM Enabled Endpoint tag)

    Posted Dec 16, 2013 04:15 AM

    Hi All,

     

    I've setup the integration between Clearpass and Soti Mobicontrol and am looking at the enformcent policies now.

     

    I want to use the "MDM Enabled" one that's memtioned in the "Clearpass MDM Integration V2 technote but I can't see it in the list of available options... 

     

    Here's what should be available:

     

    soti cppm.PNG

     

    Here's what I can see:

     

    endpoint identifier.png

     

    Soti integration appears to be ok as I can see nice healthy messages in the event viewer.

     

    Can anyone help please?


    Thanks

    James



  • 2.  RE: Clearpass / Soti Integration (MDM Enabled Endpoint tag)

    EMPLOYEE
    Posted Dec 16, 2013 05:27 AM

    You use Endpoint:MDM Enabled Equals True to check that attribute...

     

     



  • 3.  RE: Clearpass / Soti Integration (MDM Enabled Endpoint tag)

    Posted Dec 16, 2013 05:34 AM

    That's what I gathered from the technote however there is no "MDM Enabled" Endpoint tag.

     

     



  • 4.  RE: Clearpass / Soti Integration (MDM Enabled Endpoint tag)

    EMPLOYEE
    Posted Dec 16, 2013 05:36 AM

    Do you see any devices in the Endpoint database with extended attributes from the MDM? 

     

     



  • 5.  RE: Clearpass / Soti Integration (MDM Enabled Endpoint tag)

    Posted Dec 16, 2013 05:41 AM

    I can see the following:

     

    My endpoint with extended attributes.

     

    cppm endpoint.png

     

    and here are my available endpoint tags.

     

    cppm endpoint tag.png

     

    ...

     

    cppm endpoint tag1.png



  • 6.  RE: Clearpass / Soti Integration (MDM Enabled Endpoint tag)

    EMPLOYEE
    Posted Dec 16, 2013 05:49 AM

    It looks like "mdm enabled" attribute is not being populated, and that might be a bug.  What version of CPPM is this?

     

    As a workaround you can you use Endpoint: MDM Identifier Exists to check to see if the device is under management?



  • 7.  RE: Clearpass / Soti Integration (MDM Enabled Endpoint tag)

    Posted Dec 16, 2013 05:53 AM

    I'm running CPPM 6.2.2.56621.

     

    I'll have a go at using the MDM Identifier tag and see how it goes...

     

    Thanks Colin.



  • 8.  RE: Clearpass / Soti Integration (MDM Enabled Endpoint tag)

    Posted Dec 16, 2013 06:04 AM

    Also you can see my devices shows as compromised in the extended attributes however my device is running a stock ROM and is not rooted.

     

    cppm endpoint.png

     

     



  • 9.  RE: Clearpass / Soti Integration (MDM Enabled Endpoint tag)

    Posted Mar 31, 2014 09:51 AM
    Did you find a solution to this? /PoTski


  • 10.  RE: Clearpass / Soti Integration (MDM Enabled Endpoint tag)
    Best Answer

    Posted Mar 31, 2014 12:02 PM
      |   view attached

    Their was a bug identified that was fixed in the 6.3.x code.

     

    Note: Also fixed in 6.2.5

     

    From the screen shot you can see that the fields missing have been added into the SOTI endpoint attributes.