Security

last person joined: 3 hours ago 

Enterprise security using ClearPass Policy Management, ClearPass Security Exchange, IntroSpect, VIA, 360 Security Exchange, Extensions and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Device Registration and Endpoint repository

Jump to Best Answer
  • 1.  Device Registration and Endpoint repository

    Posted Jul 19, 2019 05:34 AM

    Hello , I have a question regarding Device registration .

    Our customer has 3000 Laptops purchased every month . We have deployed CPPM 6.7 for Wired NAC . 

     

    For PXE boot , MAC address has to be known so we thought of using Static Host list temporarily . But my query is

     

    1) if we do device registration , device will go to Guest Device repository ?

    2) In MAC Authentication rule for Wired , We have currently defined Authentcation souce as Endpoint repository, so we have to add Guest reposiotry also ? Also Authorization Source is currently Endpoint Repository , so authorization also needs to be updated ?

     

    3) Once device  is profiled , will it be updated to Endpoint repository ?

     

    4) Can device be removed automatically from Guest Device repository if fix any expiry timer ?

     

     



  • 2.  RE: Device Registration and Endpoint repository
    Best Answer

    Posted Jul 19, 2019 09:19 AM

    HI,

     

    1) if we do device registration , device will go to Guest Device repository ?

    Yes,if you are using guest device registration

     

    2) In MAC Authentication rule for Wired , We have currently defined Authentcation souce as Endpoint repository, so we have to add Guest reposiotry also ? Also Authorization Source is currently Endpoint Repository , so authorization also needs to be updated ?

     

    Yes

     

    3) Once device is profiled , will it be updated to Endpoint repository ?

     

    Any devcie which is trying to authenticate will get updated in endpoint repository and if device is profiled those information will also updated in Endpoint.

    4) Can device be removed automatically from Guest Device repository if fix any expiry timer ?

     

    We dont have cleanup interval option for Guest Device repository

     

    Capture.JPG



  • 3.  RE: Device Registration and Endpoint repository

    Posted Jul 19, 2019 10:13 AM
    Hi ,

    Thanks a lot

    For point 4 , we can set an expiry time while adding the device .

    So actually it will be cleaned automatically once expired .

    I have tested it ,. After expiration time it got deleted automatically after 120 seconds.



  • 4.  RE: Device Registration and Endpoint repository
    Best Answer

    Posted Jul 19, 2019 10:59 AM
    Yes , you can set an expiration time when registering the device in the Guest Device Repository



    Thank you

    Victor Fabian

    Pardon typos sent from Mobile