Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

how to use Static host list in Clearpass as Authentication server ?

This thread has been viewed 25 times
  • 1.  how to use Static host list in Clearpass as Authentication server ?

    Posted Apr 22, 2015 01:41 PM

    How to uset Static Host list as Authentication server and if it is no possible ,how to use Clearpass as Authentication server for specific service?



  • 2.  RE: how to use Static host list in Clearpass as Authentication server ?

    EMPLOYEE
    Posted Apr 22, 2015 01:44 PM
    It can be used as an authentication source for a MAC-auth service or an
    authorization source for an 802.1X service.


    What exactly are you trying to do?


  • 3.  RE: how to use Static host list in Clearpass as Authentication server ?

    Posted Apr 22, 2015 02:18 PM

    Use it in MAC service but I cant foind it in list where I add authentication source



  • 4.  RE: how to use Static host list in Clearpass as Authentication server ?

    EMPLOYEE
    Posted Apr 22, 2015 02:20 PM
    Add a new authentication source of type Static Host List.


  • 5.  RE: how to use Static host list in Clearpass as Authentication server ?

    Posted Sep 14, 2016 01:18 AM

    Tim,

     

    Can I build an Enforcement Policy rule logic (where I just enforce the [Allow Access Profile] as an action) on an 802.1x service, where I want,

    Condition 1: User exists in AD (that part is basic enough)

    Condition 2: Endpoint identifier sits in Static-Host-List (which i've already setup as an Authentication Source.. but with the host-list defined as an 'Authentication Source'.. I can't go into 'General' tab and tick the checkbox for 'Use for Authorization'... it is greyed out.. implying it's not eligible to be used as an Authorization Source... any reason why ?)

     

    With the lack of the Authentication Source of the Static-Host-List setup for Authorization also ... it means when I'm building my enforcement policy I can't auto-resolve the Static-Host-List as an 'Authorization Source'.. only the Microsoft AD one is showing..

     

    Untitled.png

     

    So.. I just want a logic AND, where user is in AD as well as endpoint identifier they are passing is in Static-Host-List.

    Unless... I just do it like this ?

    https://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/clearpass-mac-auth-matching-static-host-list/td-p/171882.

    But then, I need a separate service as it's 'MAC Auth' as a service that will trigger it.

     

    Thoughts ?



  • 6.  RE: how to use Static host list in Clearpass as Authentication server ?

    EMPLOYEE
    Posted Sep 14, 2016 01:20 AM
    Just use Connection:Client-Mac-Address BELONGS_TO_GROUP <SHL-NAME></SHL-NAME>


  • 7.  RE: how to use Static host list in Clearpass as Authentication server ?

    Posted Sep 15, 2016 04:01 PM

    To use it as an authN source..... after you've created the static list.... go create a new auth-source type=static host list and on the second tab select your newly created static-host-list....

     

    HTH

     

    ClearPass_Policy_Manager_-_Aruba_Networks.jpg

     

     

    ClearPass_Policy_Manager_-_Aruba_Networks1.jpg