Security

 View Only
last person joined: 11 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM Blacklist username

This thread has been viewed 22 times
  • 1.  CPPM Blacklist username

    Posted Mar 22, 2021 11:17 AM
    I am currently working on some cppm service about blacklisted username. I want to assign deny role on Role mapping profile, but I don't know how to filter out blacklisted username's authentication. it is not like IP or Mac which i could add them in static host list and then assign deny role by belongs_to_group.

    Could any one share alternative method to do such deny blacklisted username's authentication action.

    ------------------------------
    Shu Ming Tsang
    ------------------------------


  • 2.  RE: CPPM Blacklist username

    MVP GURU
    Posted Mar 22, 2021 12:11 PM
    Hi,

    What the source of authentication ?

    if it is AD, you can add a block ad group and make a rule if the user is member on this group,

    ------------------------------
    PowerArubaSW : Powershell Module to use Aruba Switch API for Vlan, VlanPorts, LACP, LLDP...

    PowerArubaCP: Powershell Module to use ClearPass API (create NAD, Guest...)

    PowerArubaCX: Powershell Module to use ArubaCX API (get interface/vlan/ports info)..

    ACEP / ACMX #107 / ACDX #1281
    ------------------------------



  • 3.  RE: CPPM Blacklist username

    Posted Mar 22, 2021 09:35 PM
    dot1x auth and the source is AD. Just wanna know any method to do it on CPPM side rather than do it on AD side.

    ------------------------------
    Shu Ming Tsang
    ------------------------------



  • 4.  RE: CPPM Blacklist username

    MVP GURU
    Posted Mar 23, 2021 05:13 AM
    there is no easy solution i think...

    ------------------------------
    PowerArubaSW : Powershell Module to use Aruba Switch API for Vlan, VlanPorts, LACP, LLDP...

    PowerArubaCP: Powershell Module to use ClearPass API (create NAD, Guest...)

    PowerArubaCX: Powershell Module to use ArubaCX API (get interface/vlan/ports info)..

    ACEP / ACMX #107 / ACDX #1281
    ------------------------------



  • 5.  RE: CPPM Blacklist username

    EMPLOYEE
    Posted Mar 23, 2021 05:30 AM
    What should work is adding the username in the Local Users or Guest Users database with a Role (Local Users) or Attribute, then add that database as an authorization source to your service. In role-mapping (or Enforcement) you can query the Local/Guest Users if the username is there and subject to being denied.

    Have not tested, but this should work.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------