Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Endpoint vs Authorization:[Endpoints Repository]

This thread has been viewed 18 times
  • 1.  Endpoint vs Authorization:[Endpoints Repository]

    Posted Mar 04, 2024 10:25 AM

    When adding [Endpoint Repository] as an authorization source, I have the option to build policies and role mapping based on Endpoint or based on Authorization:[Endpoints Repository]. Most of the options are the same for both options, so what is the difference and why I would use one and not the other?

    If Endpoint option is available even without adding  [Endpoints Repository] as an authorization source, is there any reason to add [Endpoints Repository] as an authorization source or even enable authorization? 



  • 2.  RE: Endpoint vs Authorization:[Endpoints Repository]

    Posted Mar 04, 2024 11:31 AM

    The Repository allows you to store endpoint information from queries triggered by other processes - most commonly DHCP Profiling. There is a lot of useful endpoint specific information that comes as a part of the DHCP Request, but obviously DHCP will not process every time AAA does. There are also many other options for storing and manipulating the Endpoint Repository database, apart from an actual AAA request. 

    The per AAA Request or AAA Accounting packets may not contain the details you need. 



    ------------------------------
    If my post was useful, please Accept Solution and Give Kudos.
    ------------------------------
    Zak Chalupka
    Principal Engineer - HPE Aruba
    ACDX | ACMP | ACSP | ACCP
    wifizak@hpe.com
    ------------------------------
    Ideas expressed here are solely my own and not necessarily that of HPE Aruba.
    ------------------------------



  • 3.  RE: Endpoint vs Authorization:[Endpoints Repository]

    Posted an hour ago

    Hi Zak,

    I know the importance if Endpoint database, my question is about the difference between Endpoint and Authorization:[Endpoints Repository]