Security

 View Only
last person joined: 7 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass OnGuard Ageneless

This thread has been viewed 19 times
  • 1.  Clearpass OnGuard Ageneless

    Posted Feb 21, 2021 06:48 PM
    Hello,
    
    I am doing a POC I needed a help, because I have already researched everywhere and I cannot find any information on how to do it or if it is supported, that is, I will explain:
    I need a client that connects via SSL VPN (Fortigate) and that a healt check is performed and based on that health check, access is guaranteed or denied. I need to use Onguard Agentless on machines that are not managed by me (guest). I found this article (https://community.arubanetworks.com/HigherLogic/System/DownloadDocumentFile.ashx?DocumentFileKey=36fb4b00-8476-449c-aa5e-e654ffb36f72&forceDialog=0) butis for onguard agent, not for agentless. Has anyone done something similar or do you know if it's possible to do it? Clearpass Version 6.9.5.131053 Fortigate Version v6.4.4 build1803 (GA) Thanks


    ------------------------------
    Frederico Gon�alves
    ------------------------------


  • 2.  RE: Clearpass OnGuard Ageneless

    EMPLOYEE
    Posted Feb 22, 2021 12:07 AM
    You need an admin account for agentless OnGuard to work. Check this link for details https://www.arubanetworks.com/techdocs/ClearPass/6.9/PolicyManager/Content/CPPM_UserGuide/OnGuard/Intro_Agentless_Onguard.htm


    ------------------------------
    Ayman Mukaddam
    ------------------------------



  • 3.  RE: Clearpass OnGuard Ageneless

    EMPLOYEE
    Posted Feb 22, 2021 03:28 AM
    For systems that or 'not yours', the dissolvable agent may be a good alternative. Or if you can have your users install the OnGuard Agent, you can do that as well.

    OnGuard requires some type of access on the devices, which is why you need to install something (Agent), have the user run something (Dissolvable), or have admin credentials (Agentless).

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------



  • 4.  RE: Clearpass OnGuard Ageneless

    Posted Feb 22, 2021 05:25 AM
    Hi Herman,
    
    Thanks for your response.
    
    So, as I understand it, the best option for external machines that my organization does not have any type of control, is the dissolvable Agent.
    
    so you have something that I can see to carry out my POC implementation.
    
    Videos, Links, PDF anything.

    Thank You.


    ------------------------------
    Frederico Gon�alves
    ------------------------------



  • 5.  RE: Clearpass OnGuard Ageneless

    EMPLOYEE
    Posted Feb 22, 2021 05:49 AM
    It's not so much if you have control over the device, it is if you can run/install the OnGuard agent on the device. If you don't have control over the device, in most cases it is hard to ask people to install your security agent on their owned device. But if they are willing to install OnGuard, it should work great.

    The best documentation that I know is the OnGuard configuration Tech Note, available at https://www.arubanetworks.com/clearpassdocs

    On page 31 it shows how to create a Web Login page for the Dissolvable Agent, but you probably should read the full document for full understanding.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------