Security

last person joined: 23 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

TechNotes Posted to support.arubanetworks.com

This thread has been viewed 27 times
  • 1.  TechNotes Posted to support.arubanetworks.com

    Posted Mar 18, 2014 04:02 PM

    Team CPPM,

     

     

    We have posted a bunch of TechNotes that I’ve written/published internally over the last 12-months to support.arubanetworks.com for general consumption,http://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/Default.aspx?EntryId=7961
     
    The List of TechNotes published is:  MDM, PKI-101, Palo-Alto, vMotion, Amigopod-Migration, Service-Routing, DELL iDRAC, OnGuard in a Cluster......
     
    I have other in DRAFT/WIP such as SLB + CPPM, CPPM in a Cluster.....I will post back here as I get these released and completed in the coming weeks....


  • 2.  RE: TechNotes Posted to support.arubanetworks.com

    EMPLOYEE
    Posted Mar 18, 2014 04:39 PM

    Thanks Danny!  Appreciate all the hard work on this!  



  • 3.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Mar 19, 2014 09:38 PM
    I had no idea there was a tech notes section on the support site. Thanks for bringing this to my attention. Great info out there!


  • 4.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Mar 19, 2014 10:18 PM

    Its actually been here for ages, but we've never posted any material here really, certainly not in past 12-months since I joined. We have all these TechNotes that I've written that are available internally and it was decided we should 'share-the-love' and make them available to our partners/customers.

     

    Hope you find some useful material/content in them. I will ensure as I create/update new docs they get posted here going forward.



  • 5.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Mar 20, 2014 11:35 AM

    Thanks for all your work on these Danny! Good stuff. Especially the certificates doc. 

     

    One question in regards to your Palo Alto v4 integration. Must the account on the firewall/panorama need to be a SuperUser / Device-Administrator? Can this be locked down further? I have a very large global customer that wants to do this integration but is wary of creating that high level account. Palo Alto account roles can be very granular so if it can be locked down more that would be fantastic. 



  • 6.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Mar 20, 2014 12:36 PM

    Josh,

     

    I'll need to do some additional testing......give me today to get through todays 'stuff' and I'll find time to get this tested and post back here for you.

     

    OK?



  • 7.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Mar 20, 2014 12:41 PM

    thank you very much indeed, some of these have been mentioned before, good to have them public now.



  • 8.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Mar 20, 2014 05:55 PM

    Josh,

     

    Sorted.

     

    So basically what I've setup and tested is this.

     

    On the PANW Under Device, Admin Roles, add a new role, say cppm-xml. Then click on the role to edit it, it gives you a pop-up windows with three tabs. Web UI, XML API & Command Line. Under Web UI I disabled everything, under XML API I disabled everything except 'User-ID agent'.

     

    Then I created a new Administrator, say cppm-admin, provide a password but change the Role from Dynamic to 'Role Based', choose the Admin Profile previously created in the drop down, then obvioulsy use this new admin profile when configuring the context server on CPPM.

     

    I've tested this with PAN-OS 6.01, the config under PAN-OS 5.x looks the same but I've NOT tested it.

     

    Hope this help you out. I'll add this snippet to my next CPPM/PANW TechNote. :-)

     

     



  • 9.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Mar 20, 2014 05:50 PM
    Sounds good. Thanks Danny.


  • 10.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Mar 21, 2014 07:06 AM
    Thanks Danny. This is exactly the info I needed.


  • 11.  RE: TechNotes Posted to support.arubanetworks.com

    Posted May 23, 2014 07:43 PM

    Team CPPM,

     

    I've just posted an updated TechNote.....  CPPM Service Routing V3.

     

    You can find it here along with all my other TechNotes.....  http://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/Default.aspx?EntryId=7961

     

     

    Have a great Weekend.....happy reading...... and go "fill your boots"..!!

     



  • 12.  RE: TechNotes Posted to support.arubanetworks.com

    EMPLOYEE
    Posted May 24, 2014 07:15 AM

    I give it 5 out of five chilis!



  • 13.  RE: TechNotes Posted to support.arubanetworks.com

    Posted May 28, 2014 06:40 PM

    Team CPPM,

     

    I’ve just published a NEW TechNote covering two Advanced Deployment use-cases for CPPM and PANW. I hope overtime to add more of these to this document……The two use cases scenarios are as follows….

     

    Configuring the PANW firewall to ingest AD Group Information and then make policy enforcement based upon the AD username passed from CPPM to PANW via the UserID API. The user will obviously be a member of one of the AD groups ingested by the PANW firewall. In our documented use case, ‘carlos’ as a member of the PLM AD group is denied access to social-networking sites. :-)

     

    Configuring the PANW firewall to make a policy enforcement based upon the HIP data sent from ClearPass. In out scenario we profile an endpoint and discover its an XP workstation, our use-case policy denies access for Windows XP due to MSFT no longer supporting this OS, we therefore deem this an unsafe OS to have in use in our enterprise.

     

    Customer/partners can find the document on the support site http://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/Default.aspx?EntryId=7961

     

     

     

    I also updated the 'Service Routing TechNote' to a V3..... found at the above URL and was posted last Friday.



  • 14.  RE: TechNotes Posted to support.arubanetworks.com

    Posted May 29, 2014 11:13 AM

    danny - the download link for the new PANW appears broken...



  • 15.  RE: TechNotes Posted to support.arubanetworks.com

    Posted May 29, 2014 11:52 AM
    I believe it was until about 11:00pst last night.... Have U tried today?


    Please excuse my errors as sent using my small useless keyboard on my smartphone.

    Regards
    --d

    Danny Jump | Technical Marketing Engineer - Networking Services | Aruba Networks
    o: 408-513-8938<408-513-8938> (diverts to cell)
    e: danny@arubanetworks.com<DANNY></DANNY>


  • 16.  RE: TechNotes Posted to support.arubanetworks.com

    Posted May 29, 2014 12:03 PM

    Still get this error:

     

    This XML file does not appear to have any style information associated with it. The document tree is shown below.
    <Error>
    <Code>AccessDenied</Code>
    <Message>Access Denied</Message>
    <RequestId>A9BF03FAD3EE1657</RequestId>
    <HostId>
    Oh9+XWGh3Cv4q9f2yAd6ktr178dniwQiCiRMaLe0xvo5bP/HEL0Ej6ML61iUdZ4L
    </HostId>
    </Error>


  • 17.  RE: TechNotes Posted to support.arubanetworks.com

    Posted May 29, 2014 12:14 PM

    I raised this to our WEB posting team last night and got a respone back saying it had been fixed..... clearly not..... I'm sorry for this issue... but I'm on it.... bear with me.



  • 18.  RE: TechNotes Posted to support.arubanetworks.com

    Posted May 30, 2014 11:49 AM

    Team CPPM,

     

    The error related to access for the new CPPM + PANW Avanced Deployment TechNote I posted a couple of days back has been resolved. Sorry for the delay.... I hope the delay was worth it.

     

    Send any feedback comments directly to me at danny@arubanetworks.com

     



  • 19.  RE: TechNotes Posted to support.arubanetworks.com

    EMPLOYEE
    Posted May 29, 2014 02:49 PM

    Danny,

     

    I noticed there's also a doc that you posted on March 18, 2014 called, ClearPass 6.X and PANW Integration V4 that's a read-me-first.  Both of these should help answer a few questions I have.

     

    Definition of HIP Objects being one thing...

     

    Thanks for working on these,

    Trent



  • 20.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Apr 24, 2017 04:09 PM
    Hi, I need to configure Clearpass/Palo Alto integration for UserID integration but I meet some issues. I have follow this Tech Note: ClearPass Palo Alto Networks Integ ration with CPPM but this does not seem to work correctly My release version is : · Clearpass Release 6.6.5 · Palo Alto PANOS 7.1.6 Indeed, when a machine authenticates itself for the first time, the clearpass transmits/updates informations to the palo alto, but when the palo alto timeout has elapsed, the clearpass information is not retransmitted/updated. On the first authentication, I can see in the show user mappin g the user information From “XML API” and username but w hen Palo Alto User identification timeout is elapsed the user From and username goes in “unknown” I also need to retrieve the user role from Clearpass, this feature seems to be available in Clearpass 6.5.5 release Can you help me to find what poses problem ? Thank you in advance, Olivier


  • 21.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Apr 24, 2017 04:44 PM

     In versions earlier than PAN-OS 7.1.5, when you did not specify a timeout value via XML API (which is the case with ClearPass), the timeout value was treated as 0, which meant that the firewall would not expire the IP address and username mapping. 

    • In PAN-OS 7.1.5 and 7.1.6, to ensure that the mapping did not expire, we must explicitly set the timeout value to 0 in the XML API Call. If you do not explicitly specify a timeout value in the API request, the firewall inherits the User-ID timeout value configured on the firewall. The configuration on the firewall is controlled by two fields under Device > User Identification > User Mapping > Cache: (i) Enable User Identification Timeout (ii) User Identification Timeout  

    o    If the checkbox “Enable User Identification timeout” is unchecked, a default timeout of 60 min is applied.

    o    If the checkbox is checked, then the timeout value specified in User Identification Timeout would be used. This can go to a maximum of 3600 minutes.

     

    We are planning to fix this on our end to include a timeout of 0 in a future release.

     

    In respect of the request about roles, you refer to 6.6.5 & 6.5.5... can you clarify please?

     

    But to add, I'm currently updating the CPPM/PANW TechNote... hoping to get this posted by the end of this week. It will include how to send/use CPPM roles in PANW and covers the timeout issue.

     



  • 22.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Apr 25, 2017 03:43 AM

    Hi Danny,

     

    Thank you for your reply. 

     

    Therefor what is your recommandation ? I think is not a good idea to set timeout at 0. All users will be always authenticated and my PANW user database can reach the limit.

     

    Concerning roles, Clearpass release note 6.6.4, 6.6.5 it's written 

     

    Enhanced Support for third parties

    • ClearPass now sends the user’s ClearPass role information to Palo Alto Networks firewalls during login. The role is unregistered from the firewall when the user logs out. For customers with lower end firewalls, it is recommended that they wait to update ClearPass as we’ll be making a further enhancement in a later release to make this a configurable option.“

    In CP 6.6.5,  Administration -> External Servers, Endpoint Context Servers -> Edit Server I see : Clearpass role : Enable Sending of applicable role information

     

    My purpose is to recover the user role assigned by CP and use it in my policy rule as a user group.

     

    Thank you



  • 23.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Jun 05, 2014 07:36 PM
    Team CPPM,
     
    Please find an updated TechNote on CPPM Profiling/Fingerprinting. I’ve published this earlier than I wanted due to multiple sources requesting this doc. Note that we will update this doc when we get 6.3.5 out the door in a couple of months time.
     
     
    Send me any feedback you want incorporating in to the next release and I’ll try to accommodate.
     
     
     


  • 24.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Jul 03, 2014 02:57 PM
    Team,
     
    I’ve just published a NEW TechNote covering OnGuard Troubleshooting.
     
     
     
    If you have any questions or queries, please feed them back to me here or direct danny@arubanetworks.com.
     
     


  • 25.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Jul 20, 2014 11:50 PM

    Team,

     

    I’ve just UPDATED the Advanced Deployment TechNote for CPPM + Palo Alto.

      

    I’ve added to this TechNote the scenario how we manipulate the username we pass to the PANW for a Guest/MAC cache deployment. A typical use-case for a user who is a Guest or for any scenario where we might MAC cache a user the issue was that we would send their MAC address to the PANW in place of their username when they re-authenticated. This new section documents how to overcome this issue. 

     

    You can find the TechNote in the usual location on the support site here:- http://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/Default.aspx?EntryId=7961



  • 26.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Aug 13, 2014 01:59 PM

    Team CPPM,

     

    I’ve posted a new TechNote written by two of our engineering team.

     

    This document provides the use cases, motivation, the list of components, requirements, the mechanics of the control and data flow and the configuration steps required to implement a solution which integrates Aruba ClearPass Access Management System (“ClearPass”), IBM Security Access Manager for Web (“ISAM for Web”), IBM Security Access Manager for Mobile (“ISAM for Mobile”), a typical Mobile Device Management (MDM) solution such as Fiberlink MaaS360 and an Aruba Wireless Controller (acting as a Network Access Server and L2 switch). The key element of the integration is an External Authentication Interface (EAI) component provided as a plugin to, and using an API supported by, ISAM for Web (“EAI Application Plugin”).

     

    The  approach  taken  is  to  use  the  SAML  standard,  modified  by  a  patent-°©‐pending  idea  invented  by  Aruba  Networks  (see  references)  and  leveraging  recent  feature  additions  in  ClearPass v6.3 and Aruba’s wireless controller software AOS v6.4 to provide two key benefits: (1) network level (i.e. L2 level) Single Sign-°©‐On (SSO) functionality to a web resource protected by ISAM for Web; and (2) to enable ISAM for Mobile to use MDM attributes collected by ClearPass (via the integration with an MDM solution)     ClearPass v6.3 and Aruba’s wireless controller software AOS v6.4 to provide two key benefits: (1) network level (i.e. L2 level) Single Sign-°©‐On (SSO) functionality to a web resource protected by ISAM for Web; and (2) to enable ISAM for Mobile to use MDM attributes collected by ClearPass (via the integration with an MDM solution)




    You can find the document in the usual place on the support site:- http://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/Default.aspx?EntryId=7961



    Go fill your boots…!!

     



  • 27.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Sep 22, 2014 04:06 PM
    Team CPPM,
     
    I’ve FINALLY published a NEW TechNote covering ClearPass and F5 Deployment. Its pretty long at 80-pages.
     
     
     
    Happy reading ….. Feedback to me please…… ‘Go knock yourself out’…..!!

     



  • 28.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Oct 10, 2014 01:58 PM
    Team,
     
    I’ve just updated the CPPM + EMM TechNote to V3. I’ve added information about SAP Afaria that we added in our 6.4 release and other minor updates through the document. I have added a large section (15-pages) on SCEP Configuration and integration, specifically with MobileIron and Airwatch.
     
     
     
     
    Happy reading – go fill your boots..!!


  • 29.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Oct 21, 2014 01:31 PM
    Team,
     
    Please find an updated TechNote on CPPM Profiling/Fingerprinting V1.1. I’ve updated a few minor blemishes in the doc but have mainly updated the section on the use/deployment of the MSFT Exchange plugin for Exchange 2013. We use the Exchange plugin as an additional source of context to capture endpoint details. There are example in the TechNote.
     
     


  • 30.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Nov 04, 2014 12:34 AM
    Team,
     
    I’ve just published a NEW TechNote providing an overview to ClearPass Exchange. This guide takes you though ClearPass Exchange and provides you with an example deployment using sendgrid.
     
     
     
     

     



  • 31.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Nov 04, 2014 12:39 AM
    Team,
     
    I’m pleased to announce that last week Splunk approved the posting of our Aruba ClearPass App for Splunk Enterprise. The App is available on the Splunk Apps store for you to download. It can be downloaded from here http://apps.splunk.com/app/1895 or by searching the Splunk App Store https://apps.splunk.com.
     
    The supporting TechNote and the Syslog XML Export file (referenced in the TechNote)  are available on the below links.
     
    We are unfortunatly unable to upload the TechNote PDF and the Syslog XML file to the Splunk App store.
     

     

     
    Please try this new initiative from the ClearPass Team. Any Questions/Feedback/Enhancement Requests can be directed to me.


  • 32.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Nov 04, 2014 07:06 PM
    Team CPPM,
     
    Please find the long awaited CPPM Cluster TechNote…..Yeah……. Straight away I need to tell you that this is not 100% complete…Booo… We're missing some of the WAN 'at-load' sizing analysis. We’ve released the TechNote as we believe that a lot of the data/information I’ve gathered should be shared now and not wait for the missing data. I’d like to have the missing data captured and documented in a V2 before the end of 2014.
     
    Customers/partners can find this on the support site here….. http://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/Default.aspx?EntryId=7961
     
     
    Please Please….. Let me know what you need/want/would-like adding to this Guide.
     
     
     


  • 33.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Mar 17, 2015 03:34 PM
    Teams,
     
    I’ve completed the ClearPass 6.5 and Fortinet integration Guide. It covers two methods of integration with Forti-Authenticator (RESTful Framework using ClearPass Exchange and RADIUS Accounting) and a single method for the FortiGate (only RADIUS Accounting).
     
     
     
     
     
    Happy reading – go fill your boots..!!….. comments and feedback/suggestions graciously accepted.


  • 34.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Mar 25, 2015 02:13 PM

    Team CPPM,

     

    I’ve completed the ClearPass 6.5 and Checkpoint Integration Guide. It covers two methods of integration, the first using our RESTful Framework using ClearPass Exchange, the second uses our new Proxy RADIUS Accounting.

     

     

    You can find the document on the support site  http://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/Default.aspx?EntryId=7961

     

    Specifically here CPPM TechNote - 3rd Party Enforcement Points (CheckPoint) v1

     

     

    Happy reading – go fill your boots..!!….. comments and feedback/suggestions graciously accepted.

     



  • 35.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Apr 06, 2015 05:46 PM

    Teams ClearPass,

     

    I’ve updated the ClearPass 6.5 and Checkpoint & Fortinet Integration TechNotes’s. The MAJOR update covers the ability to dynamically calculate the user’s role via Role Mapping before we send this to the enforcement points. Normally an easy process, but I was unable to perform this previously due to a minor UI bug, but the TechNote now covers the process. I’ve also added some minor adjustments from the feedback I received from Fortinet and CheckPoint directly.

     

    You can find the document on the support site  http://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/Default.aspx?EntryId=7961

     

    Specifically here CPPM TechNote - 3rd Party Enforcement Points (Fortinet) V1.1  and here  CPPM TechNote - 3rd Party Enforcement Points (CheckPoint) v1.1

     

     

     

    Happy reading – go fill your boots..!!….. comments and feedback/suggestions graciously accepted.



  • 36.  RE: TechNotes Posted to support.arubanetworks.com

    Posted May 28, 2015 07:08 PM

    Teams,

    I’ve completed a fairly large re-write of the ClearPass 6.5 and Palo Alto Networks integration Guide. There is a large amount of new content and specifically covers 6.5 enforcement changes (Session Notification now NOT Session restriction), updates to TAGS/DAO’s, Updates to the real-time post-auth framework and a section on Posture/Health Integration.

     

    You can find the document on the support site here..... https://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/Command/Core_Download/Default.aspx?EntryId=17560

     

    Happy reading – go fill your boots..!!….. comments and feedback/suggestions graciously accepted.



  • 37.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Jun 09, 2015 04:04 PM

     I’ve written a NEW TechNote covering some of the integration possible between CPPM and the HP Provision switches (commonly refereed to as ProCurve). The TechNote at this juncture is not as complete as we’d like but due other commitments we wanted to share with you what we have, its not as polished as normal but like I said we wanted to share what we had sooner rather than later. I expect this doc will go through multiple revisions over then next couple of months as we add new content, update what we know, correct what we have.  

     
     
    You can find the document on the support site ClearPass and ProCurve Integration TechNote V1
     
     
     
    Happy reading – go fill your boots..!!….. comments and feedback/suggestions graciously accepted.

     



  • 38.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Jun 29, 2015 04:31 PM

    Team CPPM,

     
    I’ve published a NEW integration TechNote covering ClearPass 6.5.2 and iboss WEB Security Proxy. Note that 6.5.2 is the minimum release vehicle to support this integration.
     
    You can find the document on the support site located here TechNote - 3rd Party Enforcement Points (iBoss) V1
     
     
     
    Happy reading – go fill your boots..!!….. comments and feedback/suggestions graciously accepted.


  • 39.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Jul 17, 2015 12:41 PM
    Teams,
     
    I’ve published an UPDATED integration TechNote covering ClearPass 6.5 and Checkpoint. This is an IMPORTANT update.
     
    When I was engaged with CheckPoint their plan at the time was to release a new code-train,  this was going to be the release vehicle for the RESTful integration. It came to my notice about two weeks back that they changed their plan and they have delayed the release. However, they have since released the REST integration into their existing R77 platforms via HOTFIX’s. So, I’ve built a new R77 testbed and have tested and documented this “interim” integration. Their are a few key changes, the URL POST path has been changed and the method to set the pre-shared password has also changed. I have captured these changes in the TechNote. 
     
    Customer/partners you can find the document on the support site located here CPPM TechNote - 3rd Party Enforcement Points (CheckPoint) v1.2.pdf
     
     
    Happy reading – go fill your boots..!!….. comments and feedback/suggestions graciously accepted.

     



  • 40.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Jul 29, 2015 05:53 AM

    Teams, I’ve UPDATED the Profiling TechNote adding in details of the features from the CPPM 6.5 release, such as TCP Fingerprinting, On-demand SUBNET scan, SNMP Updates and the framework we developed to allow administrator’s to perform custom device classification of unknown devices. Basically we allow admin’s to create custom rules for an endpoint using profiled attributes.

     

    You can find the document on the support site located here ClearPass Profiling TechNote V1.2.pdf

     

     

    Happy reading – go fill your boots..!!….. comments and feedback/suggestions graciously accepted.



  • 41.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Sep 08, 2015 03:30 PM

    Teams,

    I’ve published an UPDATED integration TechNote covering ClearPass 6.5.3 and CheckPoint. Whats important to note is that we have added the ability to share additional context meta-data about endpoints. This is generically available to any vendor but I’ve been working specifically with CheckPoint to have them incorporate this into the API framework, so beyond us being able to send the data to CheckPoint they can ingest and use this context in their policy enforcement, the two new exposed attributes are %device_family & %device_type.


    You can find the document on the support site located here https://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/Command/Core_Download/Default.aspx?EntryId=18814

     



  • 42.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Sep 08, 2015 05:01 PM
    Team,
     
    I’ve UPDATED our ClearPass MDM/EMM TechNote and have added a section on integration with BlackBerry BES10 server.
     
     
    You can find the document on the support site located here TechNote_ClearPass_EMM_Integration V4.pdf
     
     
     
    Happy reading – go fill your boots..!!….. comments and feedback/suggestions graciously accepted.


  • 43.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Sep 16, 2015 11:01 PM
    Teams,
     
    I’ve got another integration completed for you…!!! This is to allow ClearPass to interoperate with Intel McAfee Log Collector which works like an ‘Auth Proxy’ talking to the following Intel McAfee products allowing CPPM to share context we have about the User/IP etc. in the same way we do for other firewall/security enforcement points.
     
     
    • Integration with McAfee Next Generation Firewall 5.8 and later
    • Integration with McAfee Firewall Enterprise 8.x.x
    • Integration with McAfee Firewall Enterprise Control Center 5.x.x
    • Integration with McAfee Network Security Manager 7.5.3.11 and later
    • Integration with McAfee Data Loss Prevention 9.x.x and later
     
    Customer/partners can find the document on the support site located here CPPM TechNote - 3rd Party Enforcement Points (Intel McAfee MLC) V1.pdf
     
     
     
    Happy reading – go fill your boots..!!….. comments and feedback/suggestions graciously accepted.

     



  • 44.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Oct 17, 2015 04:38 PM

    Team ClearPass,

     

    As most of you will hopefully know come November the 1st 2015 there is a change in the way the CA's will/will-not issue Public Certificates. I've capture these changes and updated the Certificate 101 TechNote. You can find the guidance and details about that change in a 2-page section I've added.

     

    The technote is available in the usual location on the support site here:- CPPM - Certificates 101 TechNote V1.2.pdf



  • 45.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Nov 05, 2015 02:48 PM

    Team CPPM,

     

    A new configuration guide covering Unified Wireless (HP UWW) with ClearPass has been published. The guide covers three use cases:
    • 802.1X
    • MAC Authentication
    • Guest Captive Portal
    The guide is available on here on the support site.
     
     


  • 46.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Nov 09, 2015 08:35 PM
    Teams,
     
    I’ve UPDATED our ClearPass MDM/EMM TechNote and have added a section on integration with Globo GO! Enterprise EMM Server. Note that Globo is significantly more active in EMEA than NA.
     
     
    Customer and Partners can find the document on the support site located here Tech Note: ClearPass Enterprise Mobility Management Integration V5
     
     
    Happy reading – go fill your boots..!!….. comments and feedback/suggestions graciously accepted.


  • 47.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Feb 06, 2016 03:06 PM
     

    Teams,

    This NEW TechNote covers how to setup in this case a Palo-Alto Network Firewall to send CEF formatted syslog to ArcSight ESM. Have ArcSight parse this syslog, read the KVP’s and use the KVP’s to tigger API calls into ClearPass via a .py script when it detects ’threats’ coming from the PANW. Later I plan to add the configuration for CheckPoint/Juniper and potentially Fortinet to this solution.

    (Note: credit for the .py goes to Bob Filer)

    You  can find the document on the support site located here CPPM TechNote - Network Threat Detection with SIEM Integration V1.pdf<https://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/Command/Core_Download/Default.aspx?EntryId=20286>

    Happy reading – go fill your boots..!!….. comments and feedback/suggestions graciously accepted.



  • 48.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Mar 21, 2014 01:35 PM

    Team CPPM,

     

    Please find a V1 of a new TechNote covering as an introduction the reporting and graphing feature added in CPPM 6.3.0 – Graphite. This is what I refer to as a ‘sunrise’ feature where we are just providing the first early glimpses of this new feature.

     

    This is not the be-all/end-all of Graphite’s capabilities neither does this replace any additional ‘official’ documentation which should follow at a later time, this is intend to make you aware of Graphite and some of its most excellent capabilities.

     

    It can be located in the same folder as the other TechNotes I posted earlier this week, in the words of me .... 'Fill yer boots'.... which translated from british slang is 'help yourself'....Happy Reading.

     

    http://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/Default.aspx?EntryId=7961

     

     



  • 49.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Mar 31, 2014 12:23 PM

    TEAM CPPM,

     

    I just wanted to bring this back to your INBOX to make sure everyone is aware of the material I have posted to the support site recently. We wlll continue to post new documents as we release them internally here for external consumption.

     

    Please feel free to email me with any feedback so this can be incorported into future documenation releases.



  • 50.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Apr 01, 2014 07:38 AM

    Danny,

     

    I've seen several versions of parts of these documents in the Arubapedia, but these are complete and as such - awsome! 

     

    Tho - I now have wee bit many sources to look to find information. I'm now already using Airheads, Arubapedia and the Knowledge Base - which are all indexed and searchable within their realm, and through some degree - Google.. These documents aren't :(

     

    Could it be a future option to update ie. Arubapedia with the complete text and pdf as an attachment?



  • 51.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Apr 01, 2014 11:44 AM

    John,

     

    Thanks for your input - very valuable. Just to add, we had initially planned to post all my TechNotes to the AFP site, but customers don't get access, as its partner restricted. So posting to the support site 'shares the love' for ALL.

     

     

    So, I'm just the idiot that writes the material......let me go speak to our Web/Marcom team and understand what needs to happen to fulfil your request. Bear with me.



  • 52.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Apr 01, 2014 05:13 PM

    Team CPPM,

     

    Today we have added a new TechNote to the list of published documents. SAML Configuration TechNote.

     

    This document describes several SAML deployment options for ClearPass Policy Manager as both a SAML Service Provider (SP) and SAML Identity Provider (IdP). Using these SAML capabilities enables integration with numerous 3rd-­‐party SAML SPs and IdPs such as Shibboleth, simpleSAMLphp, and Google Apps.

     

    In addition, when used in conjunction with Aruba controllers running AOS 6.4, the SAML IdP capability of ClearPass enables Aruba Automatic Sign On (ASO). Using ASO, a wireless LAN user can use their 802.1X authentication to provide Single Sign On to SAML-­‐enabled applications.



  • 53.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Apr 16, 2014 02:22 PM

    Team CPPM,

     

     

    Today we have added a new TechNote to the list of published documents: - ADCS with ClearPass Onboard v1.1

     

    This document explains the use of Microsoft Active Directory Certificate Services (ADCS) to sign Onboard device TLS certificates, versus using the ClearPass Onboard Certificate Authority (CA) to do the signing.

     

    The use of ADCS provides for centralized management of TLS certificates including expiration, revocation, and deletion through ADCS. This feature has been designed to provide an easy integration of ClearPass Onboard into an existing Public Key Infrastructure (PKI) deployment based on Active Directory Certificate Services.

     

     

    You can find the doc here with all our other TechNotes. Happy reading - Fill your Boots..!!

     http://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/Default.aspx?EntryId=7961

     

     

     



  • 54.  RE: TechNotes Posted to support.arubanetworks.com

    EMPLOYEE
    Posted Apr 16, 2014 04:59 PM

    I like the new "Using ADCS with ClearPass Onboard" Tech Note posted today (4/16). Need to learn more regarding PKI's and certificates. The workflow for signing iOS is great.

     



  • 55.  RE: TechNotes Posted to support.arubanetworks.com

    Posted Apr 28, 2014 02:09 PM
    Team,
     
    Please find enclosed a new TechNote covering Integrating CPPM with ArcSight Logger. This TechNote provides a detailed configuration on how to configure CPPM to send Syslog and how to configure HP’s ArcSight Logger to receive and parse this ingested data. ArcSight Logger is a leading Security Information and Event Management (SIEM) solution that is widely deployed across many enterprise customers.
     
    You can find this posted with my other TechNotes..... specifically here …