Security

last person joined: 6 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

User Role not changing after the enforcement on the endpoint

This thread has been viewed 4 times
  • 1.  User Role not changing after the enforcement on the endpoint

    Posted Aug 13, 2015 03:33 AM

    Hi,

     

    I have configured the wireless service will checks the user health and assigns the role based on the posture status. Here I am able to find the posture status of the endpoint using clearpass onguard agent. The clearpass is enforcing the healthy role post the successful check and the role is getting updated on the controller as well, but the issue is the user laptop is not getting changed to the health role, until the disconnection and connecting back to the wireless, the moment I disconnect the laptop and connect back it gets the healthy role.

     

    Please help me….



  • 2.  RE: User Role not changing after the enforcement on the endpoint

    EMPLOYEE
    Posted Aug 13, 2015 09:08 AM
    Are you applying a role with a new vlan or just a firewall change


  • 3.  RE: User Role not changing after the enforcement on the endpoint

    Posted Aug 13, 2015 09:16 AM

    Hi,

     

    Yes, I am sending a new role with new VLAN.

     



  • 4.  RE: User Role not changing after the enforcement on the endpoint

    Posted Aug 13, 2015 10:04 AM
    You need to make sure that you either add the CoA on the Health Service (If it is an Aruba controller or switch you need add Aruba terminate profile) or you can enable the Agent bounce if you are using the persistent agent.


  • 5.  RE: User Role not changing after the enforcement on the endpoint

    Posted Aug 14, 2015 01:27 AM

    Hi,

    I have configured terminate session on the ClearPass if the agent updates the endpoint status as healthy, but still it’s not happening, if the user disconnects and connects back he is able to get the healthy profile.

     

    I am using a persistent onguard agent on the endpoint, If I need to configure bounce, please let me know how I can configure.

     

    Regards,

    PRASANTH.



  • 6.  RE: User Role not changing after the enforcement on the endpoint
    Best Answer

    Posted Aug 14, 2015 03:23 PM

    Create an Agent Enforcement Profile and Enable to Bounce Client and then you need to add this to the Posture Policy 2015-08-14 15_19_35-ClearPass Policy Manager - Aruba Networks.png

      2015-08-14 15_23_12-ClearPass Policy Manager - Aruba Networks.png