Security

 View Only
last person joined: 2 days ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Aruba Insight Management Login

This thread has been viewed 28 times
  • 1.  Aruba Insight Management Login

    Posted May 19, 2017 02:33 AM

    I'm struggeling with the Clearpass Insight Login. I've Build a Service which grant's Management Access to CPPM via Active Directory Backend with User-Role Super-Admin. Everything works fine and if a User is Logged into CPPM he's able to open Insight too. 

     

    If the User isn't Logged into CPPM and tries to Log into CP Insight he gets Rejected on the Login Web Interface. He's saying Wrong User/Password. Which is definitly wrong. If I look at the Access Tracker my Request is successfully authenticated. 

     

    My Question is. How should the Enforcement Profile look ? I've set up an Application Enforcement -> User Role - Operator Login Admin User.

     

    I Guess, I should set a specific Attribute for Authentication. I searched already but didn't found anything. 

     

    With Local Users, everything work's fine but how to set the Access Attributes for an Active Directory user and which one ?

     

    Thx in advance

     

    P.S. 

    Main Reason is to open the Links in the Email from Insight.



  • 2.  RE: Aruba Insight Management Login

    Posted May 20, 2017 03:49 AM

    I would copy the "[Insight Operator Logins]" service, add your AD to the authentication tab then alter the enforcement to allow access from your AD authentication source.

     



  • 3.  RE: Aruba Insight Management Login

    Posted May 21, 2017 11:29 PM

    Hi,

     

    You need to add Active Directory as Authorization source. If you have already added it then please share your service snap including authentication, authorztion, enforcement policy and access tracker logs.

     

    Regards,

    Milind Yashwantrao



  • 4.  RE: Aruba Insight Management Login

    Posted Jun 28, 2017 09:33 PM

    Seems like there is slightly more required than just adding AD as an Authentication or Authorization source...

     

    Has anyone got this working?



  • 5.  RE: Aruba Insight Management Login

    EMPLOYEE
    Posted Jun 29, 2017 05:16 AM

    Hi,

     

    What service type you are using to authenticate insight user againt AD?

     

    We need to use Inisght Operator login service. In

    Home » Administration » Operator Logins » Profiles we have list of profiles which we could use, if you dont want to use , create a new profile and map this profile in translation rule page.
     
    If we dont map the profile here Insight does not know what access rule policy manager is sending.
     
    use default Insight Operator login service and set enforcment based on your requirment.
     
    Regards,
    Pavan
     
    If my post addresses your query give kudos:)
     


  • 6.  RE: Aruba Insight Management Login

    Posted Jun 29, 2017 04:15 PM

    Thanks Pavan,

     

    I tried this and it looked like it should have been working OK.

     

    Could you share screenshots of a working example?



  • 7.  RE: Aruba Insight Management Login

    Posted Aug 13, 2021 03:14 PM
    J Easley,

    I have the exact problem your talking about I have tried both the [Operator Login - Admin Users] and [Operator Login - Local Users] Enforcement Profile. Had you ever come to a conclusion. Both show Access Accept in the Tracker but show username / password wrong in the Insight Portal.

    I would like to give other staff read only access into this but can't get past this.

    Thanks,
    Chris


    ------------------------------
    Christopher Calhoun
    ------------------------------



  • 8.  RE: Aruba Insight Management Login

    EMPLOYEE
    Posted Aug 24, 2021 05:49 AM
    You replied to an old discussion, information in here may be obsolete. Also, your question seems too generic to provide a useful answer.

    Please open a new discussion, add configuration, screenshots, or reach out to your Aruba partner or Aruba support.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 9.  RE: Aruba Insight Management Login

    Posted Sep 29, 2021 11:58 AM
    Hello! I'm having the same issue.
    I known this thread is old, but it keeps without solution, so I will try to use this same topic.

    Lets go... I created a service based in the default, just changed the Auth source, roles and keep the default Enforcement.
    I can see in the access tracker, that my user has been accepted (Using a local user or AD user).

    But in the Insight login, I see the error "No Privilege for Insight". 

    I think I'm missing something in the enforcement, as far as I known, there is no translation rule for Insight.
    Can someone help me to understand what I need to correct?
    (OBS: CPPM and Guest logins are working fine with their respectively services, that follows the same logic)

    Accept log for AD user in Insight:


    Accept log for Local user in Insight:



    Insight login error: 


    Services for Insight Login:










    Should I include some rule for Insight Login in my enforcement profile?

    ------------------------------
    Bruno Andrade - ACMP, ACSP, ACCP, CWNA, CCNA R&S, RCNA, ICX, SPSX
    ------------------------------



  • 10.  RE: Aruba Insight Management Login

    EMPLOYEE
    Posted Sep 30, 2021 02:34 AM
    Hi Bruno,

    The enforcement profile [Operator Login - Local users] would not be able to find the variable (Authorization:[Local User Repository]:Role_Name) value since the user is authenticating using AD. Try following the below steps.

    Steps:
    Create an admin privilege


    Create an enforcement profile to apply the admin privilege.



    Update the Insight operator login service > Enforcement policy rule to apply the profile when a user successfully authenticates using AD.

    Create an operator profile (with the same admin_privilege name) from Guest UI > Administration > Operator Logins > Profiles page and allow the appropriate access.



    ------------------------------
    Nimal Varampetran
    ------------------------------



  • 11.  RE: Aruba Insight Management Login

    Posted Sep 30, 2021 09:06 AM
    Really thanks Nimal! I did this and now it's working! :-)

    ------------------------------
    Bruno Andrade - ACMP, ACSP, ACCP, CWNA, CCNA R&S, RCNA, ICX, SPSX
    ------------------------------