Security

last person joined: 22 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Inner Identity visibility

This thread has been viewed 6 times
  • 1.  Inner Identity visibility

    Posted Feb 28, 2018 06:40 AM

    One of the really irritating things about clearpass is how it copes with inner identity user-names

     

    Instead of it being something you set up in what goes out in an Access-Accept packet, there is a general server setting 

     

    Use Inner Identity in Access-Accept Reply

     

    under the RADIUS server..... and its got to be set for each cluster member. Why on earth would you weant to have some cluster members sending an inner identity and some not ?

    <rant>

    There's a shedload of attributes you hsve to set up for individual cluster members that really really should be set up as a global parameter

     

    If you;ve got a cluster surely the idea is to make things simple. There can't be many parameters thaty need to be different once you start running a cluster

    </rant>

     

    Anyway, back to Inner identity User-Name

    Not only is it enabling it tucked away somewhere in the config you don't see it at all when looking through auth requests in Access-Tracker. It doesn't exist

     

    I proxy Accounting off to a FR server to store in a postgresql  db and I'm seeing a lot of outer User names instead of . inner ones and need to check that they're actually getting out of clearpass.

    How can I see whats getting sent out bearing ij mind this is a busy production serivice. 

     

    Guess I could proxy accounting to another FR server running in debug mode

     

    Sigh!



  • 2.  RE: Inner Identity visibility

    EMPLOYEE
    Posted Feb 28, 2018 07:07 AM

    Add this to your enforcement profile:

    Screenshot 2018-02-28 at 06.05.00.png

    You will not have to enable the "Use Inner Identity in Access-Accept Reply" parameter.