Security

last person joined: 5 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

How to change agent check timeout

This thread has been viewed 5 times
  • 1.  How to change agent check timeout

    Posted Jan 26, 2017 02:32 AM
    Hi

    I have agents installed in clients devices.
    The authentication type used is machine auth, and agent installed for healthcheck.
    I set the authentication timeout every 24 hour, but the agent sometimes doing healthcheck before this timeout expire and without any changes in clients connections or healthy status, which causing disconnections in clients because clients assigned to quarantine VLAN temporarly.

    So is there a settings to change the agent check timeout?


  • 2.  RE: How to change agent check timeout
    Best Answer

    Posted Jan 26, 2017 04:01 AM

    hc.jpg



  • 3.  RE: How to change agent check timeout

    Posted Jan 26, 2017 06:19 AM

    Thanks...

    What is the default timeout value for healthcheck?

    Also what is the "Keep-Alive Interval" option for?

     

     



  • 4.  RE: How to change agent check timeout

    Posted Jan 26, 2017 08:16 AM

    I'm not sure what the default health check interval is.

     

    From the userguide:

     

    OnGuard Health Check Interval (in hours): Specify the number of hours that OnGuard will skip health checks for healthy clients.

    NOTE: Note the following information when you set the OnGuard Health Check Interval parameter:

     You can set this parameter if OnGuard mode is set to health only.
     This parameter is valid only for wired and wireless interface types.
     This parameter is not applicable for the OnGuard Dissolvable Agent, VPN, and Other interface types.

    You can also specify the health check interval in the Agent enforcement (Configuration > Agent enforcement > New attribute) profile to create different Agent Enforcement Profiles for different users

     

    -------

     

    Keep-alive Interval (in seconds): Specify a keep-alive interval for OnGuard agents.

    The connected OnGuard Agents periodically send heart-beat (Keep-Alive) messages to ClearPass Policy Manager. This interval is defined by the Keep-alive Interval (in seconds) parameter. The default value is 60 seconds.

    ClearPass uses Keep-Alive messages to:

     Update the status of OnGuard Agents regarding OnGuard Activity.
     Issue CoA (Change of Authorization) for a Session Restrictions Enforcement Profile if OnGuard Agent is disconnected:
     Session-Check > Agent-Connection = Down
     Post-Auth-Check > Action = Disconnect

    For related information, see Session Restrictions Enforcement Profile.