Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Combining Multiple ACLs based upon Group Membership

This thread has been viewed 25 times
  • 1.  Combining Multiple ACLs based upon Group Membership

    Posted Apr 27, 2021 06:12 AM
    Hello all, I was wondering if it was possible at Clearpass authorisation stage, to be able to "evaluate all", and send multiple snippets of ACL to the authenticating device.

    EG:
    User member of HR = HR ACL
    User also member of VIP = append VIP ACL

    Conscious that typically the HR ACL would typically have an implied deny any at the end, but can we append like this at all? 

    Or even sending multiple roles to the NAD, would that work? NADs will be IAP and Aruba switches. Just to add that this HR is just one example, the intention is to have hundreds of potential combinations - clearly easier to achieve using per user VPNs etc but just wanted to explore this first.

    Thanks in advance.


  • 2.  RE: Combining Multiple ACLs based upon Group Membership

    Posted Apr 28, 2021 02:31 AM
    You can try the following. In role mapping policy use evaluate-all (default) and assign role for each group. In enforcement policy use evaluate-all and add an ACL for each role.

    In this way you will get an ACL for each group that user is member of. 

    It can become tricky with enforcement as all rules will be evaluated.

    Did you evaluate an option to use Downloadable user roles? I'm not sure if DUR can provide what you are looking for.

    Best, Gorazd

    ------------------------------
    Gorazd Kikelj
    ------------------------------



  • 3.  RE: Combining Multiple ACLs based upon Group Membership
    Best Answer

    EMPLOYEE
    Posted May 04, 2021 10:48 AM
    It's currently not supported to send multiple user-roles/dACL (ClearPass can send it, but switch/AP/controller will reject it), nor ClearPass can merge/combine multiple ACLs into a single role or ACL set. As you mentioned there is quite some complexity in there with conflicts or ordering challenges.

    Please reach out to your local Aruba SE to discuss if you have ideas on how that should work, so it can be filed as a feature request.

    For now, as mentioned, create roles for HR, HRVIP, and VIP.  I agree that doesn't scale too well.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------



  • 4.  RE: Combining Multiple ACLs based upon Group Membership

    Posted May 06, 2021 04:40 AM
    Thank you Herman, as expected, they really need a different approach to the problem.

    To use ClearPass, ideally the ACLs would append from top down through the authorisation policies as users match them (only adding the "deny any" at the end once the final ACL was added). This seems to be in line with an existing solution the customer uses for firewall VPN authorisation.

    Will push for the appropriate design.

    ------------------------------
    Tim Lloyd
    ------------------------------