Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass - Connecting from VPN with RDP

This thread has been viewed 61 times
  • 1.  Clearpass - Connecting from VPN with RDP

    Posted Jan 01, 2023 06:13 AM
    Hi,
    I setup Clearpass cluster and assign VLANs to a workstation according to its Active directory user login.
    When the workstation is logged out there is no active VLAN on the port. Only dum VLAN (999) which is not configured on the network, only locally on the switches.
    As soon as login is processed, the interface got the correct VLAN for the user.

    My problem is when a client wants to connect to the workstation with RDP. 
    When the workstation is not logged in, it has no IP address. So there isn't an option to connect to it.
    What is the best solution for that kind of problem?

    Generating a transition VLAN is the only possible way? 
    And if it does, Do you have any suggestions what is the most secure way to configure this transition VLAN?


    ------------------------------
    Best regards,
    Alon Haber
    ------------------------------


  • 2.  RE: Clearpass - Connecting from VPN with RDP

     
    Posted Jan 01, 2023 09:33 PM
    You would have to configure machine authentication on the client machine for the device to  have an ip address when logged out.

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    HPE Design and Deploy Guides: https://community.arubanetworks.com/support/migrated-knowledge-base?attachments=&communitykey=dcc83c62-1a3a-4dd8-94dc-92968ea6fff1&pageindex=0&pagesize=12&search=&sort=most_recent&viewtype=card
    ------------------------------



  • 3.  RE: Clearpass - Connecting from VPN with RDP

    Posted Jan 02, 2023 10:11 AM

    If I put the interface on vlan access 999 and have connectivity in this VLAN (with access to DHCP server and to clearpass)

    Wouldn't it be enough for the machine to get IP address in vlan 999 ?



    ------------------------------
    Best regards,
    Alon Haber
    ------------------------------