Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Need some help on Onguard.

This thread has been viewed 7 times
  • 1.  Need some help on Onguard.

    Posted Apr 18, 2015 02:01 PM

    Hi Folks,

    I have a small request,

    I want to test onguard in my lab, can someone give me some suggestion or some document to do it from scratch. I am a newbie in clearpass, so I need a doc which describe the process from scratch.

    Requirement:

    Laptop user will connect to 802.1x or captive portal enabled wired port,

    Clearpass will check if the windows firewall is enabled or not.

    If enabled then the user will get full access if not then user will move to a quaruntine  VLAN.

     

     



  • 2.  RE: Need some help on Onguard.

    EMPLOYEE
    Posted Apr 18, 2015 03:45 PM
    Have you considered using a partner? OnGuard can be tricky to set up the first time.


    Thanks,
    Tim


  • 3.  RE: Need some help on Onguard.

    Posted Apr 18, 2015 04:17 PM

    Thanks Tim for your respose.

    As I said I want to test in my LAB environment with minimal requirement. Like windows firewall is on/off device is windows 7 or  not.

    I just want to clear my concept on this.

    Please help.



  • 4.  RE: Need some help on Onguard.

    Posted Apr 20, 2015 05:37 PM
    we have been using Onguard in the lab for awhile and are in the process of deploying it to prod. I'll see what I can string together


  • 5.  RE: Need some help on Onguard.

    Posted Apr 20, 2015 07:55 PM

    Here is a quick and dirty procedure to get you up and running. Hope this helps:

     

    1. Define Health Posture Policy
      1. Under Configuration -> Posture -> Posture Policy, click Add. Name the policy, select the Onguard agent, and select your Operating System. Under the Posture Plugins tab, select the checkbox for the “ClearPass Windows Universal System Health Validator”. Click Configure.
      2. Select Windows 7 on the left, and then determine what you want to check for. In your example, select Firewall and check the for Enable checks for Windows and “A firewall application is on”. Save the configuration.
      3. Under the Rules tab, select the conditions to match for. Generally, it is best practices to use two states: Healthy and Quarantine. Define Healthy as “Passes all SHV checks” and use the Health Validator plugin. Define Quarantine as “Fails one or more SHV checks”.
      4. Save the policy.
    2. Define Posture Enforcement Policy
      1. Under Configuration -> Enforcement -> Policies, click Add. Name the policy and select the WEBAUTH enforcement type. Select [RADIUS_CoA][Aruba Terminate Session] as the Default Profile.
      2. Under the Rules tab, define three condition rules, selecting the first match:
        1. If Tips:Posture EQUALS HEALTHY, Actions: [Aruba Terminate Session], [Cisco – Terminate Session]
        2. If Tips:Posture EQUALS QUARANTINE, Actions: [Aruba Terminate Session], [Cisco – Terminate Session]
    • If Tips:Posture NOT_EQUALS HEALTHY, Actions: [Aruba Terminate Session], [Cisco – Terminate Session]
    1. Save the policy.
    1. Define Health Authentication Service
      1. Under Configuration -> Services, click Add. Select the type as “Web-based Health Check Only”. Select the Posture Compliance check box. Under Posture, select the Posture policy previously defined. The default posture token should be “Unknown.” Under the Enforcement tab, select the previously-define enforcement policy.
      2. Save the service.
    2. In your Dot1X service, under the Enforcement tab, ensure that the “Use Cached Results” checkbox is checked.
    3. Download the Onguard agent. The installer file can be found under Administration -> Agents and Software Updates -> Onguard Settings.
    4. Once the agent is installed, health check authentications should now use the newly-define service.
    5. You may now use the posture status in the Dot1X enforcement policy. When the Health auth terminates the session, the results will be cached and can be used in enforcement to assign new user role, VLAN, etc.


  • 6.  RE: Need some help on Onguard.

    Posted Apr 23, 2015 01:36 PM

    Hi efisher214,

     

    Thanks a ton for the response.

    I tried the same you mentioned, but getting error when doing WEB_Auth.

    My system is sending credential while in CPPM web-auth no auth source configured..

     

    ONG_Access_traceker error.jpg



  • 7.  RE: Need some help on Onguard.
    Best Answer

    Posted Apr 23, 2015 02:20 PM
      |   view attached

     Are you sure you selected Web-Based Health Check only service template? There should be only one condition: Type=Host, Name=CheckType, Operator=MATCHES_ALL, Value = Health

     

    This template should not require any authentication source configured. In addition, the username that you should see in the access tracker should be the mac address of the endpoint with the agent installed.