Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM; Local User DB, Attribute 'Designation', Enforcement Profile/Policy

This thread has been viewed 4 times
  • 1.  CPPM; Local User DB, Attribute 'Designation', Enforcement Profile/Policy

    Posted May 18, 2016 03:26 AM

    Hi All,

    Somewhat of a newbie with CPPM.  Bare with me.. and thanks for the impending help...

     

    I have an IAP,  RADIUS backhauled to CPPM.

    I have built a local user db on CPPM, where I have added an 'Attribute' of 'Designation' to specify a string that is used to provide 'VLAN Enforcement' on.

    Untitled 01.png

     

    I'm after some coaching on relevant Enforcement Profile and Enforcement Policy setup to be able to hook on this 'Designation' attribute to enforce the Vlan the attribute dictates.

    Then, the authentication flow is when someone enters the challenge corresponding to userid/password, they authenticate and get pinned to the appropriate vlan.

     

    For the Enforcement Profile, I presume i'm picking a radius type of 'Aruba' or 'IETF' and what attribute ?

    For the Enforcement Policy, this seems confusing.. when creating a rule, the only 'Name' option I have when specifying an Authorization Type of 'Local User Repository' is 'Enabled' and 'Role_Name'.  I can't hook on the 'Designation' ?

     

    Open for suggestions from the community.

     

    It looks like if only 'Role' is hookable then I need to create a 1:1 listing for new role's based on number of vlans I have ?



  • 2.  RE: CPPM; Local User DB, Attribute 'Designation', Enforcement Profile/Policy

    Posted May 18, 2016 04:00 AM

    Correction .. I think I can add a SQL filter query on attribute of 'Designation' in local tips postgres ?



  • 3.  RE: CPPM; Local User DB, Attribute 'Designation', Enforcement Profile/Policy
    Best Answer

    EMPLOYEE
    Posted May 18, 2016 09:04 AM
    In your enforcement policy or role map, look for "LocalUser" and then you should find your attributes. 


  • 4.  RE: CPPM; Local User DB, Attribute 'Designation', Enforcement Profile/Policy

    Posted May 18, 2016 09:31 AM

    ~embarassed~ Bingo... There's 'Designation' now.. Thanks..