Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Data port Clearpass

This thread has been viewed 4 times
  • 1.  Data port Clearpass

    Posted Sep 13, 2018 11:30 AM

    In security stand point it is necessary?

    I ask this because i see that we can add rules on the clearpass from where i can access the managment of clearpass, on the same clearpass.

     

    we will use clearpass as radius server tacacs server and also as clearpass Guest.

     

    The guest users will only have access only to the clearpass through the ports needed for that.  

    i would like to keep it simple and just use one port but im not sure if the data port was done also for security purpuses or was for something else in mind?

     

    Cheers

    Carlos



  • 2.  RE: Data port Clearpass

    EMPLOYEE
    Posted Sep 13, 2018 11:32 AM
    Using a single interface is recommended.


  • 3.  RE: Data port Clearpass

    Posted Sep 13, 2018 11:34 AM

    Thanks Tim

    Just as general knowledge, when i should use DATA port?

     

    Cheers

    Carlos



  • 4.  RE: Data port Clearpass

    EMPLOYEE
    Posted Sep 13, 2018 11:39 AM
    You shouldn’t 😊


  • 5.  RE: Data port Clearpass

    Posted Sep 13, 2018 11:41 AM

    Tim

    Why is there then? it was used before for some reason? and now is not used anymore?

     sorry Tim but i really want to know now.... :)

     

    Cheers

    Carlos



  • 6.  RE: Data port Clearpass

    EMPLOYEE
    Posted Sep 13, 2018 11:43 AM
    To offer flexibility, but we don’t recommend using it as it provides very little security value and adds complexity.


  • 7.  RE: Data port Clearpass

    Posted Sep 13, 2018 11:45 AM

    When you mean security you mean very little extra security or you mean little security at all? i mean that it offer less security than just having one port?



  • 8.  RE: Data port Clearpass

    Posted Sep 13, 2018 11:47 AM

    i mean for examplewhen you have  802.1x and the client want to add  mac authentication

    it offer little extra  security but its not worth it... it is the same????