Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

IP Phone Repository for ClearPass

This thread has been viewed 6 times
  • 1.  IP Phone Repository for ClearPass

    Posted Mar 14, 2018 03:51 PM

    During the initial roll out of 802.1x in our corporate environment we are testing IP Phones and how they authenticate against ClearPass.  We've found that it may be best to perform MAB against a local repository that we populate with IP phone MAC addresses to start with, then at some point in the future move to enabling 802.1x on the phones (if possible) and load them with certificates.

     

    We'd like to have the phones use the voice vlan assigned on each port, as we'll have numerous branch offices with different voice vlans at each attempting to authenticate.  In that scenario we can't send back a unique voice vlan and would like to just send the [Allow Access Profile].

     

    My question then is - is it a best practice to use the original [Endpoints Repository] or should we create a unique one for IP Phones specifically (then one for printers, access points, etc)?



  • 2.  RE: IP Phone Repository for ClearPass

    EMPLOYEE
    Posted Mar 14, 2018 04:16 PM
    Any manual endpoints should use Device Registration.

    What kind of switches?


  • 3.  RE: IP Phone Repository for ClearPass

    Posted Mar 14, 2018 04:17 PM

    Cisco 3650/3850 access layer switches.



  • 4.  RE: IP Phone Repository for ClearPass
    Best Answer

    EMPLOYEE
    Posted Mar 14, 2018 04:48 PM
    Take a look at the ClearPass Solution Guide for Wired Policy Enforcement. When you return the voice class via RADIUS VSA, the switch will use the locally defined voice VLAN for that session.


  • 5.  RE: IP Phone Repository for ClearPass

    Posted Mar 14, 2018 04:51 PM

    Thanks Tim! I will take a look and reply with any further updates or the resolution.



  • 6.  RE: IP Phone Repository for ClearPass

    Posted Mar 15, 2018 09:44 AM

    In our testing with MAB and Cisco 3850's, if the port has a voice vlan setup the cisco phone will get that vlan no matter if you send the device-traffic-class=voice or not. At least with auth mode of multi-auth.



  • 7.  RE: IP Phone Repository for ClearPass

    Posted Mar 16, 2018 04:35 PM

    I followed the solution guide noted by Tim and found a lot of good information on setting up this service.  Using device-traffic-class=voice also allowed our IP Phones to be placed on the correct local voice vlan rather than the data vlan.