Security

 View Only
  • 1.  ClearPass OnDemand Nmap Scan for Endpoint Profiling

    Posted Nov 17, 2024 04:53 PM
    Edited by elchy Nov 17, 2024 04:54 PM

    Hello,

    I would like to use ClearPass on-demand nmap scans to more accurately classify previously unclassified endpoints with static IPs (no DHCP). For this purpose, the generic HTTP context server has an action called "OnDemand Endpoint Scan" with the description "Perform on-demand asynchronous scan for selected endpoint and post the result to profiler".

    I have created an HTTP-based enforcement profile with the attributes 'Target server = localhost' and 'Action = OnDemand Endpoint Scan' and added it to my Mac-Auth policy. Unfortunately, no scan seems to take place even though the according policy rule is hit.

    Is there a more detailed description of this feature somewhere, e.g. what settings are required elsewhere? Has anyone already implemented this successfully and can perhaps post some screenshots of the relevant settings?

    Many thanks in advance!

    P.S. The automatic endpoint profiling in the ClearPass service is not usable for me, as this can obviously only trigger RADIUS CoA actions, but not nmap scans. And RADIUS CoA port bounce actions are only possible there if you have exactly one switch vendor type. In reality, however, there are more than one switch vendor types - sometimes side by side ;)

    -Andreas



  • 2.  RE: ClearPass OnDemand Nmap Scan for Endpoint Profiling

    Posted Nov 18, 2024 03:43 AM

    Hi Andreas.

    P.S. The automatic endpoint profiling in the ClearPass service is not usable for me, as this can obviously only trigger RADIUS CoA actions, but not nmap scans. And RADIUS CoA port bounce actions are only possible there if you have exactly one switch vendor type. In reality, however, there are more than one switch vendor types - sometimes side by side ;)

    Usually you use separate services for each switch vendor. Group switches by vendor and use NAS-IP_Address BELONGS_TO_GROUP <switch vendor group>.

    You can also use NAS-Identifier if switch support setting it.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2024
    ------------------------------



  • 3.  RE: ClearPass OnDemand Nmap Scan for Endpoint Profiling

    Posted Nov 19, 2024 07:51 AM

    NMAP offers little value in my experience.  For these endpoints you should consider a SPAN-based profiler instead.  Like Aruba Central Device Insights or Ordr.




  • 4.  RE: ClearPass OnDemand Nmap Scan for Endpoint Profiling

    Posted Nov 20, 2024 03:35 AM

    I start to playing with that setup a little bit in my lab. We'll see how it will go.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2024
    ------------------------------