Security

 View Only
last person joined: 21 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM Servce selection using UserName

This thread has been viewed 19 times
  • 1.  CPPM Servce selection using UserName

    MVP EXPERT
    Posted Mar 30, 2021 06:51 AM
    I'm currently using a "belongs-to" lit of comma delimited UserNames as part of a service selection. This is o.k for small number of users but is  a bit  of a pain as the number of users increase. Can';t use a regex  and  the "belongs to group" option in't available.

    1).Can someone remind me how to make a enhsncement request

    2). Anyyone suggest  another way of using long list of  usernames  as pasrt of a service selection ?
    Rgds
    Alex

    ------------------------------
    Alex Sharaz
    ------------------------------


  • 2.  RE: CPPM Servce selection using UserName

    MVP EXPERT
    Posted Mar 30, 2021 09:17 AM
    What is this use case? Complex service rules are not recommended in busy environments.

    ------------------------------
    Tim C
    ------------------------------



  • 3.  RE: CPPM Servce selection using UserName

    MVP EXPERT
    Posted Mar 31, 2021 03:48 AM
    We have a TACACS service for our switch estate. Issue is whole range of silly authentication attempts to access our switches. Wanted to have a service for valid users ( local users defined in clearpass) and a default deny all tacacs requests for all the silly stuff. That way if we generate a report on successful /failed auths based upon service, the silly auth attempts don’t skew the results for real valid users

    A




  • 4.  RE: CPPM Servce selection using UserName

    MVP EXPERT
    Posted Mar 31, 2021 10:30 AM
    I'd recommend you do that filtering in your report instead of in the service. You can just apply a tag (TIPS role) and then use that in your report filter.

    ------------------------------
    Tim C
    ------------------------------



  • 5.  RE: CPPM Servce selection using UserName

    Posted Apr 01, 2021 10:51 AM
    Wouldn't it be better to find out where the silly authentications are coming from and eliminating them first. I'd consider that a key element to the report if users are trying random combinations. 

    How did you end up with lots of different usernames? I use the service categorization rules for really specific eliminations. Like timms, apply a tag to different usernames or authentication of different databases/sources and use that to filter in the report.

    ------------------------------
    Jeroen Celis
    ------------------------------