Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

OnGuard Agent with WinServer 2012 R2 open RDP

This thread has been viewed 5 times
  • 1.  OnGuard Agent with WinServer 2012 R2 open RDP

    Posted 2 days ago

    With ClearPass OnGuard Agent running on WinServer 2012 R2, i have issue when user login via rdp. Agent usually have status UNKNOWN that OnGuard is not working. Show on log at Agent attems i see "ERROR ancheck 389 Query User Token failed reason = 1314" 

    So when i tryed to switch on user with admin permission of WinServer i have same Error message above. So what must i do to run OnGuard stablebility with Windows Server ? 



  • 2.  RE: OnGuard Agent with WinServer 2012 R2 open RDP

    Posted 2 days ago

    I know there are some challenges with RDP into a system, at least with 802.1X authentication, but as it's a multi-user system, it may apply to OnGuard as well. Imagine what would happen if user A is logged in to the console, user B and C through RDP? Which identity should be used then?

    If it's just about posture, you may use a health-check without authentication (Health Check Only).



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: OnGuard Agent with WinServer 2012 R2 open RDP

    Posted 2 days ago

    As my new tested, only Administrator user can login to OnGuard Agent (both of console and RDP). Another user have login button OnGuard disabled. 

    "If it's just about posture, you may use a health-check without authentication (Health Check Only)." - i dont think so cause of with Administrator users, OnGuard working well with CPPM