Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Active Directory with Clearpass cluster across multiple datacenter

This thread has been viewed 0 times
  • 1.  Active Directory with Clearpass cluster across multiple datacenter

    Posted Nov 08, 2018 02:32 PM

    I have a cluster with subscribers in two datacenters. 

    Is it possible to configure Active Directory lookup to perform actions against a dns entry for the data center the authentication is happening from as a primary source? 

    Example:
    DNS1 - AD DNS Entry for Datacenter 1
    DNS2 - AD DNS Entry for Datacenter 2

    CPPM1 - Publisher, in Datacenter 1

    CPPM2 - Subscriber, in Datacenter 1

    CPPM3 - Subscriber, in Datacenter 2

    CPPM4 - Subscriber, in Datacenter 2

    A VIP is used between the servers for authentication at Datacenter 1 and a different one is used at Datacenter 2.

    We loadbalance from the controller to authenticate against both VIP.

    Is there a way to specificy, if device is authenticating against VIP at Datacenter 1, it uses DNS1 and if it authenticates against VIP at Datacenter 2, it uses DNS 2?


    Or does this really not matter because the server only polls and caches from the publisher? 



  • 2.  RE: Active Directory with Clearpass cluster across multiple datacenter