Security

last person joined: yesterday 

Enterprise security using ClearPass Policy Management, ClearPass Security Exchange, IntroSpect, VIA, 360 Security Exchange, Extensions and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass monitoring access tracker to search Client IP

  • 1.  ClearPass monitoring access tracker to search Client IP

    Posted Jan 04, 2021 10:19 AM
    I am looking for possibility to filter Access Tracker logs by "Client IP" but can not find a filter available for the purpose on default filters, also not sure how to add a new filter. Any ideas?

    ------------------------------
    SG
    ------------------------------


  • 2.  RE: ClearPass monitoring access tracker to search Client IP

    Posted Jan 04, 2021 03:20 PM
    Here is one way that I've used before, not perfect but it works. The issue is you need to filter on the Accounting Framed-IP, this is not directly exposed in AT. So go to Data-Filter, create a new one like the below as an example...



    The in AT, change the query to use your data-filter.....


    Now you see only session for this address.....


    HTH




    ------------------------------
    Danny Jump
    "Passionate about CPPM"
    ------------------------------



  • 3.  RE: ClearPass monitoring access tracker to search Client IP

    Posted Jan 06, 2021 01:55 AM
    Hi Danny, 

    Thanks for your reply and showing me process to create/use data filter, I appreaciate it!
     
    I forgot to mention that I am using TACACS wherein I don't see adding any IP address option other than "Remote-Address" and Remote-Address is for the address of the user machine trying to connect to the NAD-Client device configured for TACACS authentication. 
    TACACS_filter_options

    Any other way to filter for "NAD-IP-Address" or "Client IP" for TACACS?


    ------------------------------
    Sunil Gajjar
    ------------------------------



  • 4.  RE: ClearPass monitoring access tracker to search Client IP

    Posted Jan 06, 2021 01:42 PM
    Would this work for you?



    ------------------------------
    Danny Jump
    "Passionate about CPPM"
    ------------------------------



  • 5.  RE: ClearPass monitoring access tracker to search Client IP

    Posted Jan 07, 2021 12:48 AM
    Cool, it works...being a novice to ClearPass I never thought NAS IP address can work as NAD IP Address.

    Thanks a bunch!

    ------------------------------
    Sunil Gajjar
    ------------------------------