Security

 View Only
last person joined: 14 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass solution to check if the user is member of nested or higher level AD group

This thread has been viewed 30 times
  • 1.  ClearPass solution to check if the user is member of nested or higher level AD group

    EMPLOYEE
    Posted Apr 01, 2021 02:16 AM
      |   view attached

    This is a short demo guide using ClearPass  to check if the user is member of nested or higher level AD group. There are many cases that the users are member of a sub group that are all part of a higher level group and you want to create a enforcement policy with fewer rules to check for the membership of a AD user group.

    Hope you'll find it useful and as always please send through your feedback for improvements.

    regards



    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------

    Attachment(s)

    pdf
    nestedAD groups-demo v0.1.pdf   1.50 MB 1 version


  • 2.  RE: ClearPass solution to check if the user is member of nested or higher level AD group

    EMPLOYEE
    Posted Apr 18, 2021 01:42 AM
      |   view attached
    I have added the second method to this technote which is based on LDAP OID (1.2.840.113556.1.4.1941)

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------

    Attachment(s)

    pdf
    nestedAD groups-demo v0.2.pdf   2.15 MB 1 version


  • 3.  RE: ClearPass solution to check if the user is member of nested or higher level AD group

    EMPLOYEE
    Posted Apr 26, 2021 05:05 AM
    Related, in video format and using the tokenGroups method instead of SubGroupmemberOf.

    Official ClearPass documentation is using tokenGroups.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------