Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM and Voip and PC connected to it

This thread has been viewed 0 times
  • 1.  CPPM and Voip and PC connected to it

    Posted Aug 31, 2018 12:13 PM

    Hi,

    Last week i've been trying to get a solution for connecting a PC to a Voip phone and to enforce a policy by the CPPM but without luck.

     

    Facts :

    • We have COMWARE5 & 7 in our network.
    • We have CPPM 6.75 deployed in a LAB environment.
    • VLAN 1050 is for voice.
    • VLAN 1023 is for corp network.
    • Yealink Voip Phone (Should be replaced with Cisco phones when project will start).

     

    As i understood from several configuration samples on the web and from my knowledge , Voice VLAN should be TAGGED and rest of the VLANS should be UNTAGGED. Port should be on Hybrid mode and PVID should be like the REST of the VLANS.

     

    Example :

    [HP-port-group-manual-pc-phone-1]port link-type hybrid

    [HP-port-group-manual-pc-phone-1]port hybrid vlan 1023 untagged

    [HP-port-group-manual-pc-phone-1]port hybrid vlan 1050 tagged

    [HP-port-group-manual-pc-phone-1]port hybrid pvid vlan 1023

    [HP-port-group-manual-pc-phone-1]undo port hybrid vlan 1

    [HP-port-group-manual-pc-phone-1]voice vlan 100 enable

     

    But what about the CPPM service, Can someone make a screenshots of his service? 

     

    Thank you

    Shmuel Mazor

     

     

     

     



  • 2.  RE: CPPM and Voip and PC connected to it

    EMPLOYEE
    Posted Aug 31, 2018 12:14 PM
    Did you follow the ClearPass Solution Guide for Wired Policy Enforcement?


  • 3.  RE: CPPM and Voip and PC connected to it

    Posted Aug 31, 2018 12:49 PM

    Yes, But not working. 

     

    There are 3 systems you need to configure. CPPM, Switch and the VOIP. How should i know if i configured them correctly ?

     

    CPPM - Policy

    Switch - Interface and global configuration

    VOIP - Interfaces tagging/untagging (2 interfaces, One for network and the 2nd of PC)

     

     

    I'm a little bit confused.