Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Insight Reports to get all endpoint information exported in csv

This thread has been viewed 38 times
  • 1.  Insight Reports to get all endpoint information exported in csv

    Posted Mar 06, 2024 01:25 PM

    Hello,

    We only have 2 services, EAP TLS and MAC  Auth in CPPM. We are trying to create a "near-time" report from clearpass insight module to export all host information that clearpass policy manager has (IP address, Device Family, Device OS, MAC address).  

    Ideally, most of the information available in "Clearpass Policy Manager > Configuration > Identity > Endpoints", would be nice if that could be reported via insight, however when I see same information in insight, most of the information is missing (e.g Device OS family:  Endpoints area show "Dell" or "Microsoft" but same thing to export in Insight we get "unknown").

    Is it possible to leverage CPPM or Insight to obtain endpoint reports that has (MAC Addr, Device family, Custom roles (that we assigned), IP address) etc.? I could get "custom roles exported in "Endpoint authentication overview report"  but its missing "Device category, family etc" which is populated in "CPPM>config > identity > endpoints".

    if i export that "identity>endpoint" list directly from clearpass, I get an xml file and got to use 'xml to csv' converter to get close to what I want but its not "near-time" (for example, show me all devices / endpoint info that connected in last 24 hours".

    Thanks



  • 2.  RE: Insight Reports to get all endpoint information exported in csv

    Posted Mar 06, 2024 03:40 PM

    In Device Insight, if you build a custom report, you can add additional Endpoint attributes to the Raw Data (CSV) Export. Those attributes will include Device Family/Category. 

    [Include raw data in output]

    Also, check your Database Retention settings in, Administration > Database Settings, to ensure Insight is storing the correct values for you report range. 



    ------------------------------
    If my post was useful, please Accept Solution and Give Kudos.
    ------------------------------
    Zak Chalupka
    Principal Engineer - HPE Aruba
    ACDX | ACMP | ACSP | ACCP
    wifizak@hpe.com
    ------------------------------
    Ideas expressed here are solely my own and not necessarily that of HPE Aruba.
    ------------------------------



  • 3.  RE: Insight Reports to get all endpoint information exported in csv

    Posted Mar 06, 2024 04:02 PM

    Zak,

    Thank you for your response.

    Is there a template available for custom reports? What report type does it take? XML or CSV? Is there a certain format that custom report expects in order to fetch the attributes from endpoint database that we are interested in?

    Thanks

    Z




  • 4.  RE: Insight Reports to get all endpoint information exported in csv

    Posted Mar 06, 2024 04:09 PM

    I may actually suggest, before writing a customer report, using the Standard Report Configuration dialogue.

    This gives you the option to Create the "Endpoint Overview" report, and include the Raw CSV. 

    Note the "include raw data in output" option

    Then you can add the the appropriate attributes/columns in the next setup dialogue:



    ------------------------------
    If my post was useful, please Accept Solution and Give Kudos.
    ------------------------------
    Zak Chalupka
    Principal Engineer - HPE Aruba
    ACDX | ACMP | ACSP | ACCP
    wifizak@hpe.com
    ------------------------------
    Ideas expressed here are solely my own and not necessarily that of HPE Aruba.
    ------------------------------



  • 5.  RE: Insight Reports to get all endpoint information exported in csv

    Posted Mar 06, 2024 04:25 PM

    Zak,

    We are passed that point.  Already generated and surprisingly, Device Family, Device OS, and all information known to our endpoint database, insight shows as Unknown to all those fields.

    that report doesnt get "Framed IP address" even though option exists in the report to pull those fields, they return as empty columns




  • 6.  RE: Insight Reports to get all endpoint information exported in csv

    Posted Mar 06, 2024 05:24 PM

    What methods are you using to profile devices and populate your Endpoint Repository? 



    ------------------------------
    If my post was useful, please Accept Solution and Give Kudos.
    ------------------------------
    Zak Chalupka
    Principal Engineer - HPE Aruba
    ACDX | ACMP | ACSP | ACCP
    wifizak@hpe.com
    ------------------------------
    Ideas expressed here are solely my own and not necessarily that of HPE Aruba.
    ------------------------------



  • 7.  RE: Insight Reports to get all endpoint information exported in csv

    Posted Mar 07, 2024 03:01 PM

    We have not enabled native profiling in CPPM, but so far data is being profiled from SNMP and DHCP.  I see those get updated in Insight, for the most part.

    See attached pictures.  

    in the first picture, I assumed under "profiling>device OS family > Microsoft corporation", that information will be carried over to Insight but no, from insight perspective, that mac address is "unknown" to all "Device OS family / category etc".

    My assumption is, we need to enable native "Profiling" under services and hope that "profiled information" gets logged in a way which Insight can pull directly.


    Z




  • 8.  RE: Insight Reports to get all endpoint information exported in csv

    Posted Mar 07, 2024 01:45 PM

    Unfortunately, we are in a similar situation with RADIUS authentication of users through a VPN device.  In Policy Manager we can see the Source IP address as End-Host Identifier, RADIUS:IETF:Calling-Station-Id, and RADIUS: IETF:Tunnel-Client-Endpoint.  I understand not getting a MAC address in the reports on this as we are authenticating a user, not a device, but the IP address is recorded in ClearPass but does not appear to populate Insight correctly or Insight does not return the information regardless of which IP address option we choose to report on.  This appears to be a bug or serious product deficiency.   I have opened a support ticket with Aruba, wish me luck.   




  • 9.  RE: Insight Reports to get all endpoint information exported in csv

    Posted Mar 07, 2024 03:18 PM

    Thanks Alan for sharing your input on this topic.

    Curious, do you have 'profiling" enabled on your Service in clearpass that serves those vpn connections? 

    Best of luck on that feature enhancement, that will be huge if they can fix that.




  • 10.  RE: Insight Reports to get all endpoint information exported in csv

    Posted Mar 11, 2024 09:52 AM

    No we do not, this is a RADIUS Identity only service validating user authentications where ClearPass is acting as the RADIUS server for an ASA device.   However, the source IP information is being captured under the following areas, but is not available for reporting apparently:

     

    Summary: End-Host Identifier

    Input: RADIUS:IETF:Calling-Station-Id

    Radius:IETF:Tunnel-Client-Endpoint

     

    We are on a C2000V virtual machine running version 6.11.7.257550 in a 2 node publisher/subscriber configuration.  Insight is on the subscriber as the majority of authentication requests are sent to the VIP which is usually the publisher.   There are no DHCP requests as the ASA assigns IPs to the client systems via the Any-Connect client communications.   Do we need to enable the Accounting proxy on this service instead?

     

    Alan Mercer

    Technical Systems Architect

    Catholic Charities

    Information Technology

    2300B Dulaney Valley Rd. 
    Timonium, Md. 21093
    667-600-2270

    amercer@cc-md.org

     

    Find on Google Maps

    I am now in a part-time role with Catholic Charities working approximately 2.5 days per week. As a result, responses to emails and phone calls may not be returned immediately. New support requests and urgent issues should be sent to the help desk at support@cc-md.org or calling (1-844-323-5477) .

     






  • 11.  RE: Insight Reports to get all endpoint information exported in csv

    Posted 12 days ago

    We have placed a Feature Enhancement request through our sales engineer.  Apparently, Aruba does not have a mechanism for feature requests through the support desk, a process change that should occur as that would make the process trackable and referenced.  But no, their process does not allow for that and requires the customer go through extra steps only to be left in the dark.   The inability to get basic information such as the source IP address from Insight to identify top attackers when large numbers of failures occur.   This is basic security logging to allow more rapid response to attacks and attribution as well as identifying how an attack transpired should a breach occur.   It's completely ludicrous that this information that is captured in the ClearPass activity logs and retained for 7 days cannot be incorporated into Insight.  Without this type of information, Insight fails to provide insight.