Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Questions about Aruba tunneled node

This thread has been viewed 3 times
  • 1.  Questions about Aruba tunneled node

    Posted Feb 22, 2018 11:05 PM

    Hi community,

     

    I have some questions regarding Aruba tunneled node feature, which is still not very clear to me even after reading some documents about it:

     

    1) In per-port tunneled node (PPTN), why do we need to configure an end-user port to access a transport vlan? The document said that the vlan is used locally inside GRE tunnel, but for what purpose? Is there any advantage/disadvantage when we configure these ports to access the same/different vlans?

     

    2) In per-user tunneled node (PUTN), the following sample configuration on the switch was given in Wired Policy Enforcement Solution Guide:

    Capture.PNG

    As far as I understand, the vlan which will be assigned to user is 604, and their traffic will be tunneled to the controller for processing (in role "quarantine"). The part that I'm not clear is that what if there's a vlan definition in "quarantine" role, say vlan 605? Then user will be assigned vlan 604 or 605?

     

    Any help would be appreciated.

     

    Thank you,



  • 2.  RE: Questions about Aruba tunneled node

    EMPLOYEE
    Posted Feb 22, 2018 11:13 PM
    In a PPTN scenario, the ports themselves should be set to the “transit” VLAN as part of the tunneling.

    For PUTN, the VLAN ID defined in the user role is the VLAN the user traffic will be assigned on the controller.


  • 3.  RE: Questions about Aruba tunneled node

    Posted Feb 22, 2018 11:44 PM

    Hi Tim,

     

    So, in PUTN, in case I made a mistake and assign a vlan in the role defined on the controller, the vlan configured in "primary" role on the switch will still be applied. Correct?



  • 4.  RE: Questions about Aruba tunneled node

    EMPLOYEE
    Posted Feb 22, 2018 11:51 PM
    Correct


  • 5.  RE: Questions about Aruba tunneled node

    Posted Feb 23, 2018 01:39 AM

    Hi Tim,

     

    About the transport vlan in PPTN, is there any specific requirement for it? I think as long as we have connectivity between the switch and controller, this vlan is not important. I'm still not sure why we need to assign switch interfaces to this vlan?



  • 6.  RE: Questions about Aruba tunneled node

    EMPLOYEE
    Posted Feb 23, 2018 07:56 AM
    It should be a dead end VLAN that only exists on both sides but is not tagged through the network.

    PUTN is recommended over PPTN.


  • 7.  RE: Questions about Aruba tunneled node

    Posted Feb 24, 2018 12:52 AM

    Hi Tim,

     

    I have some more questions regarding PUTN scenario:

     

    1) The switch will always do AAA functions. Correct?

    2) Is there an option to deny peer-to-peer traffic between clients in both scenarios: traffic being tunneled to the controller and being locally processed by the switch?



  • 8.  RE: Questions about Aruba tunneled node

    EMPLOYEE
    Posted Feb 24, 2018 12:54 AM
    1) No, with PUTN, the switch handles all AAA.

    2) Not today.


  • 9.  RE: Questions about Aruba tunneled node

    Posted Feb 24, 2018 01:00 AM

    So, there's currently no support to deny P2P traffic in both PPTN and PUTN? Because the reason I'd like to deploy tunneled node is to let the controller deny P2P traffic between wired clients just like with the wireless ones.



  • 10.  RE: Questions about Aruba tunneled node

    EMPLOYEE
    Posted Feb 24, 2018 01:09 AM
    Globally enabling it in the firewall may work, but not something I’ve tested.


  • 11.  RE: Questions about Aruba tunneled node

    Posted Feb 24, 2018 01:52 AM

    Hi Tim,

     

    If I'm not using tunneled node, does Aruba switch support an option to deny P2P traffic between wired clients - something similar to protected port on Cisco switch?



  • 12.  RE: Questions about Aruba tunneled node

    EMPLOYEE
    Posted Feb 24, 2018 09:17 AM
    Private VLAN would be the closest thing.


  • 13.  RE: Questions about Aruba tunneled node

    Posted Mar 08, 2018 02:04 AM

    Hi,

     

    I'm testing PUTN on ArubaOS switch, including DUR from CPPM and it has worked well so far. I have one question though. Does the controller also support DUR in PUTN? I mean, can we have a scenario where the switch downloads "primary" role from CPPM, then tunnel user traffic in secondary role to the controller, which in turn downloads the content of this role from CPPM?

     

    Regards,



  • 14.  RE: Questions about Aruba tunneled node

    EMPLOYEE
    Posted Mar 08, 2018 02:05 AM
    Coming soon.


  • 15.  RE: Questions about Aruba tunneled node

    Posted Mar 11, 2018 10:47 AM

    Hi,

     

    In terms of Layer 2 security, when using PPTN, does the controller support common security features (DHCP snooping, Dynamic ARP Inspection, etc.)?

     

    Regards,



  • 16.  RE: Questions about Aruba tunneled node

    Posted Mar 16, 2018 05:33 AM

    Does anyone have information about L2 security features on the controller when using PPTN? I tried to search this but found nothing.



  • 17.  RE: Questions about Aruba tunneled node

    Posted Aug 15, 2018 08:57 AM

    Hello!

     

    I tested this in my lab and it works for me just fine in the following way:

     

    I have an Aruba switch with PPTN to Aruba controller, where I have a captive portal profile set to authentication. The authentication is sent to Clearpass, which then reads Active Directory, and based on group membership, it sends back Aruba VSA role to controller. I have a separate service for wired authentication on CPPM and I have a separate wired roles and wireless roles (example: aruba_wifi/aruba_wired) on controller. I have a policy in the wired roles that denies user to all private ip. This way they can surf the net, but the two client can't communicate with each other even if they are in the same role.

     

    Hope this helps.

     

    Daniel