Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Onguard with non supported devices

This thread has been viewed 2 times
  • 1.  Onguard with non supported devices

    Posted Oct 22, 2014 03:42 PM

    Hello, im configuring something simple.

     

    A guest portal which does a verification just if its has a antivirus or not

    This work great for Windows, MACOS 

     

    But if i try to connect an android it says that its not suppported.   Im aware is not supported but there is a way to not to scan in the same SSID the android devices?, i mean  not to scan the android devices but to scan the windows and mac os deivces?

     

     

    Cheers

    Carlos



  • 2.  RE: Onguard with non supported devices

    EMPLOYEE
    Posted Oct 22, 2014 03:46 PM

    Why not use the endpoint DB as an authz source and then use logic like:

     

    IF DEVICE TYPE = Computer AND OS FAMILY MATCHES_ANY WIndows/OSX, then send back the role for the OnGuard portal.

     

    For everything else, just hand out a restricted role that will allow what you require based on policy.



  • 3.  RE: Onguard with non supported devices

    Posted Oct 22, 2014 03:55 PM

    It doesnt matter that on the SSID on the selft registration i got  Require a successful OnGuard health check?


    Sorry i just kind of lost with clearpass i have been doing really simple things so far.

     

    Cheers

    Carlos



  • 4.  RE: Onguard with non supported devices

    EMPLOYEE
    Posted Oct 22, 2014 07:12 PM

    You will need to create two captive portals. One with OnGuard and one without. In the controller you will then setup two roles so when the device first connects it will get a role based on the device type. You will need to create that rule in the service.

     

    Here is an example of my MDM service. You will need to do the opposite just like Seth suggested.

     

    Screen Shot 2014-10-22 at 6.09.38 PM.png



  • 5.  RE: Onguard with non supported devices

    Posted Oct 24, 2014 09:16 AM

    Thank you