Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Installing intune extension failed on clearpass with proxy settings

This thread has been viewed 24 times
  • 1.  Installing intune extension failed on clearpass with proxy settings

    Posted Oct 13, 2023 05:41 AM

    We are currently running clearpass cluster with version 6.9.13 and want to make an integration with Microsoft Intune. Our cluster is behind a firewall that normally has no internet access. We use a proxy server to retrieve firmware updatec, etc. Downloading firmware etc works fine with a proxy server.

    Now we want to install the Microsoft Intune extension and get the following error message: Error creating extension instance: Download failed with status 500.

    When we make a wireshark trace, we see that clearpass wants to go directly to the internet and not via the proxy server. According to the clearpass documentation, the proxy settings of the cppm should be inherited.

    Is anyone familiar with this problem?



  • 2.  RE: Installing intune extension failed on clearpass with proxy settings

    Posted Oct 13, 2023 10:06 AM

    IIRC I've downloaded extensions with a proxy configured under the server settings in the past.  This was on 6.10 though. 

    https://community.arubanetworks.com/blogs/esupport1/2022/12/02/firewallproxy-host-whitelist-for-clearpass-extensions




  • 3.  RE: Installing intune extension failed on clearpass with proxy settings

    MVP EXPERT
    Posted Oct 14, 2023 02:45 AM
    Having exactly the same problem here with 6.11.4
    A
    Sent from my iPhone




  • 4.  RE: Installing intune extension failed on clearpass with proxy settings

    EMPLOYEE
    Posted Oct 16, 2023 05:42 AM

    There is a known issue CP‑49373/CP‑49665: the configured HTTP Proxy settings were not used when downloading ClearPass Extensions.

    Fixed in 6.11.3 (so alexs-nd, please open a TAC case if you see this on 6.11.4); 

    https://www.arubanetworks.com/techdocs/ClearPass/CP_ReleaseNotes_6.x.x/Default.htm#ReleaseNotes/Resolved/Resolved-6.11.3.htm?Highlight=49373

    This issue seems to be in 6.10 as well, so maybe also in 6.9 but I can't find the full details on versions. Best would be to open a TAC case as they seem to be able to fix this issue for you.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: Installing intune extension failed on clearpass with proxy settings

    Posted Oct 31, 2023 11:16 AM

    I was able to solve the problem with TAC support. Appears in 6.9 as well. there is a missing line in a config file that needs to be created manually.






  • 6.  RE: Installing intune extension failed on clearpass with proxy settings

    Posted Feb 29, 2024 04:22 PM

    I can't speak to 6.11.4, but I can confirm that the bug is still present (or was re-introduced) in 6.11.7. 

    I see proxy being honored for initial request to clearpass.arubanetworks.com, then a subsequent direct connection attempt to registry-1.docker.io which we block. This results in a 500 when attempting to install the UAP extension: "Error creating extension instance: Download failed with status 500".




  • 7.  RE: Installing intune extension failed on clearpass with proxy settings

    MVP EXPERT
    Posted Feb 29, 2024 05:30 PM
    Yeah, I gave up trying to download it in 6.11.7…. But at least with 6.12.1 you can upload the extension to clearpass
    A