Security

 View Only
last person joined: 11 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Device Profiler - IP Helper address

This thread has been viewed 36 times
  • 1.  ClearPass Device Profiler - IP Helper address

    Posted Jun 03, 2021 08:39 AM
    Hi all,

    I having issue's with using an IP helper-address to profile devices. 

    We are using Dell S4248-ON (core) and Dell N2048 (Access) switches.
    The core switch already has two IP helper-addresses configured, one for the primary Windows DHCP-server, and another one for the secondary Windows DHCP-server.

    Once we add a third IP helper-address pointing to our ClearPass Publisher Server, clients will no longer receive a (new) DHCP lease (ipconfig /renew will time out). Once we configure a random server to be the third 'ip helper-address', the clients receives a new lease again.. ClearPass is not suppose to answer to a DHCP request right? 

    My question: It seems that the problem lays at ClearPass and not at the switch configuration; Do we need additional configuration at ClearPass in order to get device profiling to work? 

    Thanks in advance!

    ------------------------------
    Lex
    ------------------------------


  • 2.  RE: ClearPass Device Profiler - IP Helper address

    Posted Jun 03, 2021 11:40 AM
    ClearPass will consume and then discard the DHCP messages, it NEVER replies to them. 

    CPPM will look for DHCP Options 55 & 60 {VCI} from the DISCOVER message and DHCPREQUEST, these are used specifically for the fingerprinting process.

    ------------------------------
    Danny Jump
    "Passionate about CPPM"
    ------------------------------



  • 3.  RE: ClearPass Device Profiler - IP Helper address

    Posted Jun 04, 2021 03:39 AM
    Hi Danny,

    Thanks for your clarification on the DHCP collector(s), that makes sense. 
    Do you have any idea on what is going wrong? Do I need additional configuration at the ClearPass side to resolve this issue / get device profiling to work?

    ------------------------------
    Lex
    ------------------------------



  • 4.  RE: ClearPass Device Profiler - IP Helper address

    EMPLOYEE
    Posted Jun 04, 2021 05:34 AM
    As Danny mentioned, ClearPass is completely passive from a switch perspective. Most switches will send relay the DHCP requests to all of your configured helpers/relays, and ClearPass will discard, the other servers (hopefully) will respond. One thing I may think of could be that the ip helper on the switch is 'too intelligent' and forwards the DHCP to only one of the configured IPs, which if it selects the ClearPass will result in a timeout.

    The issue lies most probably in the switch. I would check if you see the DHCP requests arriving at the actual DHCP server, and if that server responds. From there find out where the issue is, and as mentioned it is really unlikely that the ClearPass has anything to do with this.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------