Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

OnGuard healthy check reassessment period

This thread has been viewed 19 times
  • 1.  OnGuard healthy check reassessment period

    Posted Jul 06, 2023 06:47 AM

    Can we config OnGuard healthy check reassessment period or not?

    We need Onguard agent health checks every 1 hour without disconnecting and connecting to the network. When we test ongaurd agent only  healthy check when first network connect.   



  • 2.  RE: OnGuard healthy check reassessment period

    EMPLOYEE
    Posted Jul 06, 2023 07:50 AM

    When OnGuard is running, it does contineous testing. If one test fails, it will reach out to ClearPass actively. It depends a bit on the type of test, but in my experience the agent detects changes within minutes or even seconds.

    If you need a report regardless status change, you may try setting the Health Check Interval in your Agent enforcement (or in the Onguard global settings).



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: OnGuard healthy check reassessment period

    Posted Jul 10, 2023 03:44 AM

    Thank you, Herman Robers.

     I tried this solution: when we use the health check interval, we cannot put a retry button on the agent (when we put a retry button on the client, the clearpass server will ignore staus from the client for 1 hour). We need a healthy check interval client and a retry button too because some times the agent does not auto-check.




  • 4.  RE: OnGuard healthy check reassessment period

    EMPLOYEE
    Posted Jul 10, 2023 04:25 AM

    Ah, I didn't know that setting the interval removes the retry button. Maybe it's good to open a TAC case to find the optimal solution in your case, if no other responses are posted here.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: OnGuard healthy check reassessment period

    Posted Jul 10, 2023 06:33 AM

    Thank you Herman Robers, I will try open a TAC case.




  • 6.  RE: OnGuard healthy check reassessment period

    Posted Jul 10, 2023 03:49 AM
    Hi guys, I found a new feature on 6.11.x, under Universal Health Validator, there is Grace Period parameter. Can we use this to check ?  Or grace period is "just when onguard results in Unhealthy (from Healthy), then it will stay healthy until x period set in Grace Period setting" ?

    Maybe in the new user guide we can see what this means but i just want saw this posting and want  to respond to it . Cheers





  • 7.  RE: OnGuard healthy check reassessment period

    Posted Jul 10, 2023 06:44 AM

    Thank you, Matchabear. That solution, I think, is good, but in my case, we found the client did not reboot the PC, and when cache health expires, the client cannot use the network.