Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Onguard problem

This thread has been viewed 49 times
  • 1.  Clearpass Onguard problem

    Posted 4 days ago

    Hello!

    Recently I have configured a basic Onguard - Posture policy on our Clearpass to check windows Firewall and some registry state. And it is working fine in general.

    But, during on the first WLAN connection of the day the User stucks in UNKOWN(0) posture state and had to rejoin to get in HEALTHY(0). Because the WLAN connection is faster than the Onguard scan, so during the first connection the Posture state is UNKOWN(0) and based on this the client gets the quarantine ACL.

    Example log:

    What am I missing? How can I configure this to change the client state based on the Posture state change?

    Thanks



  • 2.  RE: Clearpass Onguard problem

    Posted 4 days ago



  • 3.  RE: Clearpass Onguard problem

    Posted 3 days ago

    When using Onguard there is the following dependency:
    1. First WLAN dot.1x-Auth - Posture state is UNKOWN, because no status has yet been transmitted by the agent

    2. Web-Auth by the agent - posture status is transmitted, a port bounce must occur at this point so that the posture status can be evaluated.

    3. Second WLAN dot.1x-Auth - At this point, the dot.1x service must evaluate the posture code. However, it does not see it because the dot1x-wlan service and the web-auth service do not communicate with each other.

    The trick is to activate "Use Cached Results" in the Enforcement tab.

    Then the dot.1x-Auth service can read the posture code from the endpoint cache. Then everything works as desired.




    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACX - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 4.  RE: Clearpass Onguard problem

    Posted 2 days ago

    The tricky part is that I have configured this feature already. (Based on the official guide)

    And yet the port bounce does not happens :(

    Do I have to configure something on the AP - WLAN side? like enable Dynamic Authorization?   I did it already, and did not solve it.




  • 5.  RE: Clearpass Onguard problem

    Posted 2 days ago

    Yes, I know, it's a difficult topic, but please don't give up.
    The port bounce does not happen automatically, you have to configure it. In the web-auth service you have to send either coa in a RADIUS_DynAuthZ or bounce-client in an agent-enforcement-profile. If you use coa, you must also set up Dynamic Authorization in the WLAN. With agent enforcement, the agent bounces the port on the client side independently of Dynamic Authorization. It's a matter of taste, I use the agent variant.

    Have you watched any videos of Herman? He explains it very well.

    https://m.youtube.com/watch?v=l5Rt2K8KJiE



    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACX - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 6.  RE: Clearpass Onguard problem

    Posted yesterday

    Yeah I viewed that video, and configured everything like Herman.

    Yet it seems the [ArubaOS Wireless - Terminate Session] enforcement profile has no effect, because after the Posture Scan, there is no connection bounce or anything like that.

    So I am clueless now.




  • 7.  RE: Clearpass Onguard problem

    Posted 19 hours ago

    CoA is probably not working.
    Make sure that ClearPass and WLAN controller synchronize the original time with the same NTP server. 
    Make sure that RADIUS CoA is enabled in the ClearPass network device.
    ClerPass uses UDP 3799 for CoA by default. Make sure that ClearPass can reach the controller via this port.

    Authorization Radius Authorization or RFC 3576 Server must also be configured in the WLAN controller.

    Please post enforcement from the web-auth service. 



    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACX - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 8.  RE: Clearpass Onguard problem

    Posted 19 hours ago

    Hello!

    Webauth Enforcement: 

    What are configurations steps of the Agent Bounce method?

    And what are the COA steps?   I simply cannot find information about them.

    Thanks.




  • 9.  RE: Clearpass Onguard problem

    EMPLOYEE
    Posted an hour ago

    When troubleshooting CoA, first check with Access Tracker that you see Accounting data, and use the 'Change Status' in Access Tracker to test a manual CoA first, before expecting that a policy triggered CoA works.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 10.  RE: Clearpass Onguard problem

    Posted 49 minutes ago

    Hello Herman!

     

    If I configure an Agent Bounce, it works, but it bounces the Wifi adapter everytime a click ont he Rescan button.

    Furthermore after the first scan of the day, its kinda weird.

     

    I mean I successfully authenticate via Cert and after the OnGuard Scan the agent turns off the Wifi and turns on and the machine authenticates again and gets the full access.

     

    The CoA version would me more smooth right? without this WLAN interface bounce right?

     

     

    I have tested your „Change Status" suggestion and only tha Agent Bounce worked, the „Aruba Wireless – Termiante Session" version had no effect at all.

     

    Thanks.

     

    --

    Gloster Infokommunikacios Nyrt. Logo

    Tar Máté / Senior rendszermérnök
    tar.mate@gloster.hu

    Gloster Networks Kft.
    Office: +3614568010
    2142 Nagytarcsa, Csonka János utca 1/a.

    Support telefonszám: +3617002000

    http://www.gloster.hu/