Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Aruba Clearpass and JAMF Casper suite

This thread has been viewed 1 times
  • 1.  Aruba Clearpass and JAMF Casper suite

    Posted Apr 15, 2014 08:00 AM

    Could someone tell me what the benefits are by adding your Jamf Casper JSS server to aruba clearpass server?  We currently own both products and was wondering what kind of functionality we would gain?  I planned on looking at NAC soltuiions this summer that would tie into our Casper server, so i assume this might be why?



  • 2.  RE: Aruba Clearpass and JAMF Casper suite

    Posted Apr 15, 2014 09:16 AM
      |   view attached

    You can use ClearPass to integrate with a number of MDM solutions, includng JAMF Casper.   In doing so, you can obtain additional information about the connecting device; and then use it your policy evaluation and enforcement.  The following table summarizes what is pulled from JAMF.   How you use the data is up to you and how you want to secure your network.   For example, you may want to use the "compromised" or "last check in" tags to make some decisions.  I've also attached the MDM integration guide for your reference.

     

    cppm-jamf.png

    Attachment(s)



  • 3.  RE: Aruba Clearpass and JAMF Casper suite

    Posted Apr 15, 2014 12:43 PM

    Please read my TechNote already attached, if you have additional question after consuming the info please come back to us.



  • 4.  RE: Aruba Clearpass and JAMF Casper suite

    Posted Apr 17, 2014 08:20 AM

    NPSD,

    Are there any devices which do not belong to your organization in your JAMF?  Are you doing BYOD in your environment?

     

    We use JAMF to manage our Apple products.  When BYOD became project to get working in our environment, we started using it for device identification.  If a product exists in JAMF, it is one of our devices.  We then use that information plus their AD group membership to assign a role.  If an apple product is not in our JAMF then it gets less access through a BYOD related role.