Security

last person joined: 22 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Passing Aruba-Device-Type from controller to CPPM

This thread has been viewed 2 times
  • 1.  Passing Aruba-Device-Type from controller to CPPM

    Posted Dec 08, 2014 02:31 PM

    Is there a way to pass Aruba-Device-Type from a controller to CPPM?  i.e. Controller indicates device type is Chromebook and passes that information to CPPM so it can make a decision.  We're trying to ID chromebooks dynamically with MAC authentication (MAC in CPPM endpoint database).  Is this possible?



  • 2.  RE: Passing Aruba-Device-Type from controller to CPPM

    EMPLOYEE
    Posted Dec 08, 2014 02:32 PM

    Yes, it is automatically included in the RADIUS request. You can reference it in the role map or enforcement using RADIUS:Aruba:Aruba-Device-Type



  • 3.  RE: Passing Aruba-Device-Type from controller to CPPM

    Posted Dec 08, 2014 02:33 PM

    OK then that is the part that is broken I think.   We do not see it in the input tab since the AOS upgrade.  That is how it was set up before the AOS upgrade and it worked.  Since AOS upgrade, it is no joy...



  • 4.  RE: Passing Aruba-Device-Type from controller to CPPM

    EMPLOYEE
    Posted Dec 08, 2014 02:34 PM

    What code? I see it in 6.4.2.2

     

    radius-device-type.JPG



  • 5.  RE: Passing Aruba-Device-Type from controller to CPPM

    Posted Dec 08, 2014 02:41 PM

    Opps, sorry.

     

    AOS 6.3.1.13

    CPPM 6.3.4.xxxx

     

    We just upgrade the AOS code.  We're hoping to upgrade CPPM version in a couple of weeks as we didn't want to change AOS & CPPM at the same time for troubleshooting reasons (if there was a problem).



  • 6.  RE: Passing Aruba-Device-Type from controller to CPPM

    EMPLOYEE
    Posted Dec 08, 2014 02:42 PM

    Are you seeing the device type in the user table?



  • 7.  RE: Passing Aruba-Device-Type from controller to CPPM

    Posted Dec 08, 2014 02:49 PM

    Yes, I am seeing it there.  It is also (as expected) showing up in the WebUI as well.

     

    TAC just called and they are going to check on versioning information in regards to this situation.  I swear it was working before the AOS upgrade but I'm old & forget things sometimes.



  • 8.  RE: Passing Aruba-Device-Type from controller to CPPM

    EMPLOYEE
    Posted Dec 08, 2014 03:09 PM

    One other thing that you could possibly do is configure IF-MAP between the Aruba Controller and ClearPass, so that it passes that information from http user agent strings and mdns queries to clearpass from the device-type table of the controller:  http://www.arubanetworks.com/techdocs/ArubaOS_63_Web_Help/Web_Help_Index.htm#ArubaFrameStyles/Management_Utilities/CPPM-ifmap.htm

     

     



  • 9.  RE: Passing Aruba-Device-Type from controller to CPPM

    Posted Dec 08, 2014 04:06 PM

    I did a packet capture and radius is returning the fingerprint of the OS correctly to CPPM.  CPPM is not dealing with it properly for some reason.