Security

 View Only
last person joined: yesterday 

Enterprise security using ClearPass Policy Management, ClearPass Security Exchange, IntroSpect, VIA, 360 Security Exchange, Extensions and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Policy Manager 6.10 Release Notifications

This thread has been viewed 85 times
  Thread closed by the administrator, not accepting new replies.
  • 1.  ClearPass Policy Manager 6.10 Release Notifications

    EMPLOYEE
    Posted May 12, 2021 05:33 PM
    No replies, thread closed.

    We are pleased to announce the immediate availability of ClearPass Policy Manager 6.10.0!  In addition to bug fixes, this release also includes several new features that our Engineering and QA team have worked tirelessly to include:

     

    Inclusive Language Changes

    Why is this interesting? This release introduces changes in multiple areas of ClearPass Policy Manager to reflect the commitment to inclusive language.  Changes have been made in multiple UI screens, APIs, CLI commands, database table names, and audit events to chage to a more inclusive language for all our customers.

     

    Updated HPE Passport Interactions

    Why is this interesting? Customers need to enter a valid HPE Passport (HPP) credential to enable ClearPass Policy Manager to download updates (patches, fingerprints, etc.).  When HPP password changes occur the ClearPass Policy Manager is not aware of this and frequently continues to use the old credentials until the account is locked out and TAC needs to be called.  The HPP system now supports a token-based workflow that will only ever use a current username/password workflow to issue a token that the ClearPass Policy Manager will renew automatically.

     

    Local Node Authentication Source Status Widget

    Why is this interesting? It may sound like a long title, but the status of each Active Directory or LDAP server is now displayed in the Policy Manager dashboard.  This provides a quick view to the sources that are up or down as well as reasons that problems are being observed.  This allows administrators to see on a per-node basis if they are having any communication issues with these servers.

     

    Policy Hit Counter

    Why is this interesting? Customers are now able to display the number of times Service Policies are hit within specified times to determine how frequently policies are used.

     

    Endpoint Cleanup on Last Seen

    Why is this interesting? Not every endpoint is profiled making it difficult to cleanup systems that are no longer relevant on the network from the endpoint database.  Customers can now select options to remove known and unknown devices from the endpoint database based on the last time it authenticated on the network.

     

    Updated Dictionaries and Templates

    Why is this interesting? The latest TACACS+ & RADIUS dictionaries have been updated for multiple vendors and Dynamic Authorization templates have been added or updated to provide the latest functionality when working with infrastructure systems.  This includes Arista, Arista CVP, Cisco, Cisco-Meraki, Juniper, Silver Peak, and the latest Aruba updates.

     

    Document Consolidation

    Why is this interesting? The TechPubs team has spent significant time updating the formats of ClearPass Policy Manager related documentation to align with other Aruba product formats (such as AOS).  This includes unifying all installation guides into a single document that includes installation, upgrading, and deployment of VPC systems.

    As always, please take note of the 'Changes of Behaviors' section of the release notes (https://www.arubanetworks.com/techdocs/ClearPass/CP_ReleaseNotes_6.10.x/Default.htm).

     

    Software images are available on the Aruba Support Portal and support updates (clearpass.arubanetworks.com) portal already.  New AMI images will be available within 24 hours for customers who request these.  New images Azure images will be available within the Azure Marketplace in approximately 2 weeks.

     

    A big thanks and congratulations to the ClearPass Engineering, ClearPass QA and TechPubs teams for reaching this milestone!

     

    Best regards,

    The ClearPass Team


  • 2.  RE: ClearPass Policy Manager 6.10 Release Notifications

    EMPLOYEE
    Posted Jul 27, 2021 10:02 AM
    No replies, thread closed.

    Hello All,

     

    We are pleased to announce the immediate availability of ClearPass Policy Manager 6.10.1!  This release includes multiple bug fixes for all customers.

    This release does not include new features but does include several Behavior Changes that everyone is encouraged to review in the release notes posting. 

    As always, please take note of the 'Changes of Behaviors' section of the release notes (https://www.arubanetworks.com/techdocs/ClearPass/CP_ReleaseNotes_6.10.x/Default.htm).

     

    The update images have been posted to the Aruba Support Portal (ASP) and the software updates portal.

     

    A big thanks and congratulations to the ClearPass Engineering, ClearPass QA and TechPubs teams for reaching this milestone!

     

    Best regards,

    The ClearPass Team

    ------------------------------
    Bryan Lechner
    ------------------------------



  • 3.  RE: ClearPass Policy Manager 6.10 Release Notifications

    EMPLOYEE
    Posted Oct 11, 2021 07:52 PM
    No replies, thread closed.

    Hello All,

    We are pleased to announce the immediate availability of ClearPass Policy Manager 6.10.2!  In addition to bug fixes, this release also includes several new features that our Engineering and QA team have worked tirelessly to include:

    Local Profiling (when using CPDI)

    Why is this interesting? While many people have enjoyed the integration with CPDI in Central to get additional profiling information, systems that are not managed by Central required customers to select between using the local profiling and the CPDI capabilities.  This release allows customers to use BOTH CPDI profiling and local profiling capabilities for non-Central managed parts of the network

     

    OnGuard IPv6 Support

    Why is this interesting? Customers using dual stack networks can now leverage OnGuard persistent agent (PA) and native dissolvable agent (DA) clients to communicate information with CPPM over IPv4 or IPv6 networks.  Note that this is not currently supporting agentless OnGuard (AOG) or pure IPv6 networks.

    DUR Enhanced with AOS-CX 10.08 and later

    Why is this interesting? Administrators are now able to configure end-to-end primary and secondary roles with AOS-CX switches that use UBT with AOS Mobility Controllers & Gateways in the downloadable user role configuration screens (both Standard & Advanced modes)

    Kerberos DNS URI Support

    Why is this interesting? CPPM will now use Kerberos DNS URI lookups if traditional DNS is not available during network join events.

    As always, please take note of the 'Changes of Behaviors' section of the release notes (https://www.arubanetworks.com/techdocs/ClearPass/CP_ReleaseNotes_6.10.x/Default.htm).

    The update images have been posted to the Aruba Support Portal (ASP) and the software updates portal.

    A big thanks and congratulations to the ClearPass Engineering, ClearPass QA and TechPubs teams for reaching this milestone!

    Best regards,

    The ClearPass Team

    ------------------------------
    Bryan Lechner
    ------------------------------



  • 4.  RE: ClearPass Policy Manager 6.10 Release Notifications

    EMPLOYEE
    Posted Dec 15, 2021 07:12 PM
    No replies, thread closed.

    Hello All,

     

    We are pleased to announce the immediate availability of ClearPass Policy Manager 6.10.3!  In addition to bug fixes, this release also includes several new features that our Engineering and QA team have worked tirelessly to include:

     

    Event Viewer warning if RADIUS Proxy Target is down

    Why is this interesting? ClearPass has alerted for AD/LDAP sources not being available for several years now, but we are not including the ability to note if a RADIUS proxy target is not available as well.  This is important for customers using remote proxy systems for RADIUS requests that may not respond in a timely manner.

     

    Device Groups have selectable display values

    Why is this interesting? For several years the display in Device Groups have been limited to only 20 results, customers now have the option to select the displayed size limits between 20-1000 to display.

     

    Endpoint Context Server use when Insight is down

    Why is this interesting? If Insight servers are not available (such as during upgrades) the context server actions to communicate information to Palo Alto Network systems are still available.  When the Insight server is back the system will automatically return to it.

     

    OnGuard support for Windows 11 and macOS Monterey

    Why is this interesting? Customers in the 6.10 release now have access to the same support of latest OS versions with OnGuard that were recently released in 6.9 already.

     

    As always, please take note of the 'Changes of Behaviors' section of the release notes (https://www.arubanetworks.com/techdocs/ClearPass/CP_ReleaseNotes_6.10.x/Default.htm).

     

    The update images have been posted to the Aruba Support Portal (ASP) and the software updates portal.

     

    A big thanks and congratulations to the ClearPass Engineering, ClearPass QA and TechPubs teams for reaching this milestone!

     

    Best regards,

    The ClearPass Team



    ------------------------------
    Bryan Lechner
    ------------------------------



  • 5.  RE: ClearPass Policy Manager 6.10 Release Notifications

    EMPLOYEE
    Posted Mar 02, 2022 02:23 PM
    No replies, thread closed.

    Hello All,

     

    We are pleased to announce the immediate availability of ClearPass Policy Manager 6.10.4!  In addition to bug fixes, this release also includes several new features that our Engineering and QA teams have worked tirelessly to include:

     

    Password Change Prompt on macOS

    Why is this interesting? End users using macOS are now prompted to change their password during the authentication.  This is a change in behavior as well as an improved user experience.

     

    New DUR field for AOS-CX – Re-Authentication Period

    Why is this interesting? Downloadable user role (DUR) functionality with AOS-CX switches now allows the use of a random timer for re-authentication intervals.  This will then return a random time for each user authentication that occurs, preventing the possibility of having many endpoints triggering re-authentication during the same time.

     

    Unresponsive Authorization Sources Generate Event Viewer Message

    Why is this interesting? Event Viewer messages are now generated when LDAP, SQL, and HTTPS/S authorization sources are found to be unresponsive.  This allows the event to be exported to remote systems (e.g., Syslog) that will be able to trigger additional alerts beyond those done by ClearPass itself.

    As always, please take note of the "Changes of Behaviors" section of the release notes https://www.arubanetworks.com/techdocs/ClearPass/CP_ReleaseNotes_6.10.x/Default.htm.

     

    The update images are posted to the Aruba Support Portal (ASP) and the Software Updates portal.

     

    A big thanks and congratulations to the ClearPass Engineering, ClearPass QA, and TechPubs teams for reaching this milestone!

     

    Best regards,

    The ClearPass Team

    ------------------------------
    Bryan Lechner
    ------------------------------



  • 6.  RE: ClearPass Policy Manager 6.10 Release Notifications

    EMPLOYEE
    Posted May 04, 2022 02:10 PM
    No replies, thread closed.

    Hello All,

     

    We are pleased to announce the immediate availability of ClearPass Policy Manager 6.10.5!  In addition to bug fixes, this release also includes several new features that our Engineering and QA team have worked tirelessly to include:

     

    MSCHAP Configuration Options

    Why is this interesting? Two new configuration options are available for customers using MSCHAP and MSCHAPv2 authentications.  MSCHAPv2 has the option to set the number of retries (0-5) that a supplicant is allowed to retry, this helps prevent locking out accounts.  MSCHAP has the option to return a Reject rather than the Challenge response allowing Cisco VPN clients/servers to trigger password change workflows.


    As always, please take note of the 'Changes of Behaviors' section of the release notes https://www.arubanetworks.com/techdocs/ClearPass/CP_ReleaseNotes_6.10.x/Default.htm.

    The update images will shortly post to the Aruba Support Portal (ASP) and the software updates portal.

    A big thanks and congratulations to the ClearPass Engineering, ClearPass QA and TechPubs teams for reaching this milestone!

     

    Best regards,

    The ClearPass Team


  • 7.  RE: ClearPass Policy Manager 6.10 Release Notifications

    EMPLOYEE
    Posted 12 hours ago
    No replies, thread closed.

    Hello All, 

    We are pleased to announce the immediate availability of ClearPass Policy Manager 6.10.6!  In addition to bug fixes, this release also includes several new features that our Engineering and QA team have worked tirelessly to include:

    Onboard works with Microsoft Intune Onboard Extension

    Why is this interesting? Microsoft Intune does not include a Certificate Authority (CA) but does require a certificate for multiple workflows (view the Microsoft Intune v6 Tech Note).  This modification allows for a new ClearPass Extension "Microsoft Intune Onboard Enrollment" to be used that will then allow the ClearPass Onboard system to properly work with Intune managed clients to automatically provision certificates on managed devices against the CPPM Onboard CA. 

    As always, please take note of the 'Changes of Behaviors' section of the release notes https://www.arubanetworks.com/techdocs/ClearPass/CP_ReleaseNotes_6.10.x/Default.htm.

    The update images have been posted to the Aruba Support Portal (ASP) and the software updates portal.

    A big thanks and congratulations to the ClearPass Engineering, ClearPass QA and TechPubs teams for reaching this milestone!

    Best regards,

    The ClearPass Team