Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass user isolation by Fortigate virus detection

This thread has been viewed 1 times
  • 1.  Clearpass user isolation by Fortigate virus detection

    Posted Feb 22, 2018 09:07 AM

    Hi All,

     

    I've set up a Clearpass server as a radius server and a Fortigate firewall.

     

    Can i connect those two together with syslog or something? So when a user is blocked by fortigate because of virus isues. Clearpass recieves a message and puts the user in a restricted vlan.

     

    When the user is a Smartphone he gets a different threatment than a IPcam. for example. a smartphone get blocked by three violations and an IPcam immediately.

     

    Someone know a solutions?

    Thanks

     

     



  • 2.  RE: Clearpass user isolation by Fortigate virus detection

    EMPLOYEE
    Posted Feb 22, 2018 09:11 AM
    You (or your ClearPass Partner) would need to build an Ingress Event Engine dictionary for Fortigate. We do not have one available today.


  • 3.  RE: Clearpass user isolation by Fortigate virus detection

    Posted Feb 27, 2018 04:35 AM

    Thanks i'll try that.

    But what option do i chose for "configuration->Network->event sources"?

    only checkpoint, infoblox, palo alto and Juniper are availabe.

    does the vendor matter or is it for all syslog the same?

     

     



  • 4.  RE: Clearpass user isolation by Fortigate virus detection

    Posted Sep 20, 2018 05:42 PM

    Have you had any success with this?

    I note that the following link states dictionaries for ingress control with fortinet are included as of 6.6.1

    https://gold.nvc.co.jp/document/aruba/Releasenote/ClearPass/clearpass6.6.x/ClearPass_6.6.1_ReleaseNotes.pdf

     

    The new Ingress Event Engine enables ClearPass to process Syslog events from third-party devices to make

    policy changes in realtime. For example: (#28446, #29415, #30254, #32451)

    -  A third-party device could signal to a ClearPass appliance to quarantine or block a user if the contents indicate the presence of malware.

    - Syslog dictionaries from leading vendors such as Palo Alto Networks, Checkpoint, Juniper Networks, and Fortinet are included by default.