Security

last person joined: 18 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Receptionist user based on AD Group/User settings

This thread has been viewed 6 times
  • 1.  Receptionist user based on AD Group/User settings

    Posted Nov 15, 2017 04:58 AM

    Hi Guys,

     

    first things first:

     

    we're using several Aruba instant "farms" with guest's captive portals. 

    We are currently using ClearPass Guest Webinterface to provision time limited guest tickets to our clients. These Tickets are created by serveral receptionists. 

     

    Currently, the receptionists use the same user which is located on the local ClearPass Server Database with the privilege level "Receptionist".

    (ClearPassPolicyManager -> Administration -> Users and Privs -> Admin Users)

     

    We now want to change this to a personalized AD User. We added an authentication method and the AD-Connection for this method works fine, but I cannot find an option how to add AD users to this "Receptionist" Role.

     

    can you help me out?

     

    br

    Patzed



  • 2.  RE: Receptionist user based on AD Group/User settings
    Best Answer

    Posted Nov 15, 2017 06:24 AM

    1. You need to create an enforcement profile which maps the "admin_privilages" attribute to the "Receptionist" operator profile.

     

    admin_priv.jpg

    2. Then copy the [Guest Operator Logins] service. Modify the copied service by adding your active directory auth source. Then add some role mapping to identify your reception users. E.g. 

     

    admin_mapping.jpg

    3. Then copy the built in enforcement policy [Guest Operator Logins] and modify the copy. Add a condition to map the [Reception Operator] role (from the role mapping in section 2) to the enforcement profile (from section 1). E.g.

     

     

     

    admin_enforcemn.jpg

    4. Move your copied [Guest Operator Logins] service above the default built in [Guest Operator Logins] service.

     

    NOTE: Do not delete anything default from the copied [Guest Operator Logins] service.



  • 3.  RE: Receptionist user based on AD Group/User settings

    Posted Nov 15, 2017 08:00 AM
      |   view attached

    Hello,

     

    many thanks for you description. 

     

    can you give me a hint how to move enforment policies? They are numbered, but I cannot move them up or down ?!

     

    br

    Patzed



  • 4.  RE: Receptionist user based on AD Group/User settings

    Posted Nov 15, 2017 08:05 AM
    Just click on one of the rules in the enforcement policy and click on the "move up" or "move down" button below them..


  • 5.  RE: Receptionist user based on AD Group/User settings

    Posted Nov 15, 2017 08:08 AM

    Hey J,

     

    ah - inside the Policy in the rule Tab! No matter if there is an default Guest operator login policie as shown in my screenshot?!

     

    I'll test the procedure soon and give a feedback.

     

    many thanks so far.



  • 6.  RE: Receptionist user based on AD Group/User settings

    Posted Nov 15, 2017 08:54 AM

    Its really strange that the access is denied because of a policy as the policy is a copy of a working, local authentication policy.. hmm

     

    CPPM _Deny.jpg

    CPPM _Deny_2.jpg



  • 7.  RE: Receptionist user based on AD Group/User settings

    Posted Nov 15, 2017 09:59 AM

    It's likely that your enforcement policy doesn't match the authentication request so is applying the default deny policy.



  • 8.  RE: Receptionist user based on AD Group/User settings

    Posted Nov 15, 2017 10:00 AM

    I modified the policy to the Default profile "Operator Login AD Users". its working now.

     

    CPPM _allow_ad_.jpg



  • 9.  RE: Receptionist user based on AD Group/User settings

    EMPLOYEE
    Posted Nov 15, 2017 10:05 AM
    By doing that, you've effectively allowed anyone that successfully authenticates to access this. Please find out why your rule isn't matching instead.


  • 10.  RE: Receptionist user based on AD Group/User settings

    Posted Nov 15, 2017 10:34 AM
    Yeah, don't leave it like that.


  • 11.  RE: Receptionist user based on AD Group/User settings

    Posted Nov 15, 2017 10:48 AM

    your're right. Thats not the intention..

    can you give me a hint where to search? I defined the "memberof" Field

    with the content" Reception" and added my test user to the group "reception", but it seems not to work..

     

    1.: I replaced the default profile back to "Deny"

     

    CPPM _Deny_3.jpg

     

     



  • 12.  RE: Receptionist user based on AD Group/User settings

    EMPLOYEE
    Posted Nov 15, 2017 10:54 AM
    Look in access tracker under the input tab in authorization. Do you see the group listed?

    Also, it's recommended to use the "Group" attribute instead of memberOf.


  • 13.  RE: Receptionist user based on AD Group/User settings

    Posted Nov 15, 2017 11:05 AM

    As I wrote, I changed back the settings back to defualt: deny, but we can still logon with any AD authenticated user, thats really weird. Do we need to restart any service?

     

    I changed the attributes to the following:

    CPPM _group.jpg

    Yes, I see the group listed.

     



  • 14.  RE: Receptionist user based on AD Group/User settings

    Posted Nov 15, 2017 11:29 AM
    Can you post a screenshot of the access tracker, input tab authorization section?


  • 15.  RE: Receptionist user based on AD Group/User settings

    Posted Nov 15, 2017 11:41 AM

    hey J,

     

    aruba_shot1.jpg

     

    the Input tab is huge, contains hundreds of groups (yes I know...) but not the requested group "reception"

     

    Authentiucation not still works for users with AND without the correct AD group. 



  • 16.  RE: Receptionist user based on AD Group/User settings

    EMPLOYEE
    Posted Nov 15, 2017 11:44 AM
    I thought you said it was there?

    Is this a nested group?


  • 17.  RE: Receptionist user based on AD Group/User settings

    Posted Nov 15, 2017 11:46 AM

    Ah sorry for the missunderstanding.

    Yes, its there, but I'm now logging in with a user that should not be able to logon because the user isnt part of the group, but it still works for all AD users as it seems.

     

    IF I use my Test-User which is in the group, the group is also recognized in the authorization tab.



  • 18.  RE: Receptionist user based on AD Group/User settings

    EMPLOYEE
    Posted Nov 15, 2017 11:50 AM
    Please work with your Aruba ClearPass partner or Aruba TAC. It's very difficult to troubleshoot in real-time in a forum setting.


  • 19.  RE: Receptionist user based on AD Group/User settings

    Posted Nov 15, 2017 12:05 PM

    that can be complicated because we changed the distri..

     

    it should be easy to find out why the authorization is granted without beeing in the listed group?

     

    however, ill try to get official support.

     

    Is there any possibilty to open a tac via mail as end customer?

     

    br

    patzed



  • 20.  RE: Receptionist user based on AD Group/User settings

    EMPLOYEE
    Posted Nov 16, 2017 08:33 AM

    If you need an example of how you can set it up, please check this ClearPass video series. More specific, Wireless #3 - Wireless Role Based Access for the AD group mapping, and  Guest #6 - Operator Profiles for ClearPass Guest backend login (Receptionist).



  • 21.  RE: Receptionist user based on AD Group/User settings

    Posted Nov 16, 2017 08:43 AM

    Thanks all for the support.

     

    I contacted HPE via the MyNetworking Account and finally got the solution now.

     

    The issue was hidden in den Service -> Roles -> Default Role

     

    This default Role was set to the same Receptionist Role, so the Fallback Case was an authorization as well where it should be a Role which is not authorized.

     

    Authorization is now working with [Group "CONTAINS" -> e.g.Reception] Condition

     

    br

    Patzed

     

     



  • 22.  RE: Receptionist user based on AD Group/User settings

    Posted Apr 02, 2019 08:33 AM

    What will the query looks like if we want to pull the OU membership of the computer Object? I have the Authoziration enable for the service but it is only pulling the info in the first image, info looks like is only querying the hostDnsName, hostOperatingSystem from the DC:

    query1.PNGquery2.PNGquery3.PNG