Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Import Endpoints Fingerprint

This thread has been viewed 6 times
  • 1.  Import Endpoints Fingerprint

    Posted Sep 12, 2017 09:32 AM

    Dear All,

     

    How can i import the Endpoints Fingertpring while importing Endpoints in clearpass?

     

    I have tried the following:

     

    <Endpoint macVendor="" macAddress="d0bf9c260c4f" status="Unknown">
    <EndpointProfile conflict="false" category="Audio/Video Devices" hostname="xxx" staticIP="true" ipAddress="x.x.x.x"/>

     

    It is only importing the macAddress

     

    Please advise.

     

    Best Regards,

    Maurice



  • 2.  RE: Import Endpoints Fingerprint

    EMPLOYEE
    Posted Sep 12, 2017 09:35 AM
    You cannot.


  • 3.  RE: Import Endpoints Fingerprint

    Posted Sep 12, 2017 09:40 AM
    @cappalli wrote:
    You cannot.

    Is there any other way to import devices in another way?

     

    My concern is to create a service to bypass 802.1x for Cisco Phones. I was planning to do the below: import the devices, create a service with a condition: Type: Endpoints Reposotiry and in the Name set the Hostname.

     

    Is there any other way to do that?

     

    Best Regards,

    Maurice 



  • 4.  RE: Import Endpoints Fingerprint

    EMPLOYEE
    Posted Sep 12, 2017 10:02 AM
    The devices will be profiled the first time they connect and then profiling information can be leveraged. You can also use the phone’s factory certificate for EAP-TLS (this is the recommended, secure way).


  • 5.  RE: Import Endpoints Fingerprint

    EMPLOYEE
    Posted Sep 12, 2017 10:02 AM
    The devices will be profiled the first time they connect and then profiling information can be leveraged. You can also use the phone’s factory certificate for EAP-TLS (this is the recommended, secure way).


  • 6.  RE: Import Endpoints Fingerprint

    Posted Sep 13, 2017 12:57 AM

    Hi Tim,

     

    As i understand from your reply, that the devices will be shown by theirselfs in the endpoints without having to do anyting on clearpass?

     

    If yes, is there anything that should be done on the switch side?

     

    Regards,

    Maurice



  • 7.  RE: Import Endpoints Fingerprint

    Posted Sep 13, 2017 02:54 AM

    There are multiple ways to profile endpoints. Read more about that here:

     

    Clearpass profiling technote

     

    That said - on your switch you will have to add mab (mac auth if no 1x).

    I believe you will find more information about how to do that here:

     

    Clearpass Wired 802.1x with Cisco

     

    If you're not using Cisco then you should still get the basics of how it's done from that document.