Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM & how to filter extensionAttributes in AD

This thread has been viewed 11 times
  • 1.  CPPM & how to filter extensionAttributes in AD

    Posted Aug 28, 2019 09:39 AM

    Because of a company reorganisation we have to redesign our NAC-setup. Some entities may not communicate with other entities etc. The AD will not spil, nor the server setup.

    However network wise it will split. So I wanted to see what my options are here.

     

    My first attempt was to use an extensionAttribute in the AD with a specific value per PC;

    ad.JPG

    Then, in the CPPM, under authentication sources I added this attribute;

    src.JPG

    This should provide the link between the AD's attribute and CPPM, wright?

     

    Next was to specify the enforcement policy;

    pol.JPG

     

    I thought this would do the trick, but instead it falls back on the radius VLAN Enforcement profile (seen on line 3);

    out.JPG

     

     

    What am I missing here?

    Or do I have to review my approach? 

    Please advice!



  • 2.  RE: CPPM & how to filter extensionAttributes in AD

    EMPLOYEE
    Posted Aug 28, 2019 11:20 AM

    Check access tracker log to see if it is fetching proper attributes and also try clear cache and check the status.



  • 3.  RE: CPPM & how to filter extensionAttributes in AD

    Posted Aug 29, 2019 04:41 AM

    I cleared the cache and checked the log. I cannot see that CPPM is fetching this attribute.
    However, if I check the AD via the filteroption in the authentication sources, I clearly see that the CPPM is able to see this attribute. But why doesn't it try to fetch it during the authentication?

    filter.JPG



  • 4.  RE: CPPM & how to filter extensionAttributes in AD
    Best Answer

    EMPLOYEE
    Posted Aug 29, 2019 11:39 AM

    I just checked in the lab and it works for me. Do you see the extension attribute in Access Tracker under Input - Authorization Attributes:

    Screen Shot 2019-08-29 at 17.24.06.png

    If it doesn't show, what could be the reason is that the Base DN in your AD authentication server could be set to the Users OU and for that reason not searching in the CN=Computers. Make sure that the Base DN is set high enough (I have it set to dc=arubalab,dc=com, not cn=Users,dc=arubalab,dc=com) to include your computers in the search.

     

    Also a role mapping from the extension attribute to a ClearPass role works fine:

    Screen Shot 2019-08-29 at 17.36.27.png

    Role Computer is assigned:

    Screen Shot 2019-08-29 at 17.35.51.png

    The most important step is to see the attribute show up in Access Tracker. Unless it is shown there, there is no use of looking in matching/mapping.



  • 5.  RE: CPPM & how to filter extensionAttributes in AD

    Posted Aug 30, 2019 03:04 AM

    Thanks for the clear explanation.

    The base DN wasn't set high enough, but despite solving this still the same result.
    I don't see the authorization attributes at all in a request, how does one configure this?

     

     



  • 6.  RE: CPPM & how to filter extensionAttributes in AD

    Posted Aug 30, 2019 04:19 AM

    Nevermind, got it



  • 7.  RE: CPPM & how to filter extensionAttributes in AD

    Posted Sep 01, 2020 09:41 AM

    hi - how did you get this working ?



  • 8.  RE: CPPM & how to filter extensionAttributes in AD

    Posted Sep 01, 2020 09:58 AM

    Hi,
    Yes, we got it up and running.
    Make sure you set the base dn high enough.
    Under authentication sources, in your AD, configure the attribute you want to fetch, and try to get it there. Once that's ok, see if you can fetch it during a authentication attempt. In the log you'll see how you can filter it in the policies, and then link it to a profile or role.

    Check how Herman described it!



  • 9.  RE: CPPM & how to filter extensionAttributes in AD

    Posted Aug 29, 2019 04:21 AM

    might be a typo in the Enforcement rule ? (ASESO vs ACESO)



  • 10.  RE: CPPM & how to filter extensionAttributes in AD

    Posted Aug 29, 2019 04:33 AM

    Nice catch, it was indeed a typo, but it was corrected before this posted this issue.