Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM, DNS, Certificates and Master/Backup

This thread has been viewed 0 times
  • 1.  CPPM, DNS, Certificates and Master/Backup

    Posted Aug 29, 2013 01:03 PM

    I'm hoping someone can enlighten me here!!

     

    We have two controllers (6.1) acting as Master/Backup, both have IP presence in the management subnet (loopback and SVI) and guest subnet (SVI). VRRP is currently only configured in the management subnet using the SVI addresses.

     

    There is also a single CPPM (6.2) which also has IP presence in both the management and guest subnets.

     

    Firstly, does anyone know which interface the CPPM uses as it's source and for which protocols etc...?

     

    Secondly, what is the preferred way of configuring DNS and Certificates? My assumption on this point is that;

    1) Setup VRRP on the guest subnet and configure DNS to resolve to this address (for NAS login from the CPPM).

    2) Create a CSR using OpenSSL which uses the above DNS as it's Common Name but include SAN addresses for their individual hostnames. Get this signed and imported into both controllers.

     

    The CPPM appliance will then be configured as normal with it's own publicly signed certificate (for iOS onboarding) and a matching DNS entry created for the address on the guest subnet.

     

    Any guidance would be appreciated.



  • 2.  RE: CPPM, DNS, Certificates and Master/Backup