Security

 View Only
last person joined: 2 days ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Use GuestUser:SponsorName with LDAP

This thread has been viewed 17 times
  • 1.  Use GuestUser:SponsorName with LDAP

    Posted Apr 21, 2021 06:32 PM
    Hi,

    How can I get GuestUser:SponsorName to work with LDAP queries, under Policy Manager?
    I want to block all mac track devices if the Sponsor user account is disabled or blocked.
    I can see GuestUser:sponsor_email, but am unable to use the GuestUser:sponsorname / sponsor username.

    Thanks

    ------------------------------
    Ricardo Duarte
    ------------------------------


  • 2.  RE: Use GuestUser:SponsorName with LDAP

    MVP GURU
    Posted Apr 27, 2021 07:54 AM
    Hi Ricard,

    Do you have add do_ldap... field ?

    ------------------------------
    PowerArubaSW : Powershell Module to use Aruba Switch API for Vlan, VlanPorts, LACP, LLDP...

    PowerArubaCP: Powershell Module to use ClearPass API (create NAD, Guest...)

    PowerArubaCX: Powershell Module to use ArubaCX API (get interface/vlan/ports info)..

    ACEP / ACMX #107 / ACDX #1281
    ------------------------------



  • 3.  RE: Use GuestUser:SponsorName with LDAP

    Posted Apr 27, 2021 12:50 PM
    Hi,

    Yes, I do alread have that.
    The problem is not inside "Guest". After registration, I can't query LDAP under Tips Services to do a real-time check for ldap account.
    Because I can't get ClearPass to make queries to LDAP using GuestUser:sponsorname.

    To make it somehow clear, what I want to do is to have an LDAP Authentication source that uses the following filter:

    (&(objectClass=user)(sAMaccountName=%{GuestUser:sponsorname}) 

    But ClearPass does not fill the GuestUser:sponsorname in the query.

    It does work if I use:

    (&(objectClass=user)(sAMaccountName=%{GuestUser:sponsor_email}) 


    But for some particular reason, this query will not work for me in my scenario. I need to query by sponsorname.




    ------------------------------
    Ricardo Duarte
    ------------------------------



  • 4.  RE: Use GuestUser:SponsorName with LDAP

    MVP GURU
    Posted Apr 27, 2021 03:53 PM
    Hi,

    It is better to open a issue on TAC...

    ------------------------------
    PowerArubaSW : Powershell Module to use Aruba Switch API for Vlan, VlanPorts, LACP, LLDP...

    PowerArubaCP: Powershell Module to use ClearPass API (create NAD, Guest...)

    PowerArubaCX: Powershell Module to use ArubaCX API (get interface/vlan/ports info)..

    ACEP / ACMX #107 / ACDX #1281
    ------------------------------