Security

Reply
Contributor II
Posts: 67
Registered: ‎06-29-2014

cppm wired and wireless posture config

hi,

 

i have cppm , i have configured wrilessservice with posture for employee,

and we want to configure wired service with posture,,

 

 have already created posture policy and profiles for them, and its work good with wireless service,

 

what am asking,, do i have to create another posture policy for wired service also,

 

for wired i have created mac auth service and wired service ,under wired service i have create policy with rules to check if the tips equal to user auth and if tips equla to mac auth, and to chech if the user equal to healthy,,

 

can i use the same posture service, of wirless? did the posture service which i have created  enough?

 

thanks

Guru Elite
Posts: 8,759
Registered: ‎09-08-2010

Re: cppm wired and wireless posture config

You can use the same posture policy, you just might want to use a separate enforcement policy if you use different roles and VLANs on the wired side.


Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Contributor II
Posts: 67
Registered: ‎06-29-2014

Re: cppm wired and wireless posture config

i have already created another policy for and am using Dacl cisco switch,

 

for healthy and unhealthystatus should i add  Dacl profile , or only for healthy status

Guru Elite
Posts: 8,759
Registered: ‎09-08-2010

Re: cppm wired and wireless posture config

If you want to treat the unhealthy clients differently, then you'll need an unhealthy enforcement profile.

Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Contributor II
Posts: 67
Registered: ‎06-29-2014

Re: cppm wired and wireless posture config

i have already created healthy profille (full access) and unhealthy profile(limited acces)

 

 

i just confused when i i sgin let say full acccess prfile for a rule should i add Dacl profile also with full access profile (the 2 profiles)

 

and should i sagin limited access profile with Dacl profile to another rule?

 

 

or should i add Dacl profile to the rule which check if its healthy?

 

Contributor II
Posts: 67
Registered: ‎06-29-2014

Re: cppm wired and wireless posture config

where should i add Dacl cisco profile???

Guru Elite
Posts: 8,759
Registered: ‎09-08-2010

Re: cppm wired and wireless posture config

In your wired enforcement policy. Check for tips posture status unhealthy.

Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Contributor II
Posts: 67
Registered: ‎06-29-2014

Re: cppm wired and wireless posture config

/thankssss,

 

 

i have 4 services

wireless service

posture service

wired service

mac auth service

 

is that right way or orderin services?

MVP
Posts: 1,414
Registered: ‎11-30-2011

Re: cppm wired and wireless posture config

that is dificult to say without knowing their matching configuration. in principle the order is fine if  the correct services are hit, but you will have to look at that yourself.

Search Airheads
Showing results for 
Search instead for 
Did you mean: