Security

last person joined: 11 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Can you partition the user database in ClearPass with different admin for each%3F

This thread has been viewed 0 times
  • 1.  Can you partition the user database in ClearPass with different admin for each%3F

    Posted Oct 20, 2016 05:03 AM

    I have a customer who needs to provide a multi-tenant WLAN solution in their managed office building.  Can we partition the ClearPass user database and allow a 'tenant admin' access only to 'their' partition of the user database?



  • 2.  RE: Can you partition the user database in ClearPass with different admin for each%3F

    EMPLOYEE
    Posted Oct 20, 2016 05:06 AM
    For local user accounts, no you cannot.

    For guest user accounts, you can use operator profiles to limit users to seeing accounts created by the same operator profile.


  • 3.  RE: Can you partition the user database in ClearPass with different admin for each%3F

    Posted Oct 20, 2016 05:11 AM

    OK, thanks for the prompt reply, as always, Tim - as we need to offer secure (802.1x + encrypted) access, I don't think Guest will cut the mustard here.  Perhaps we could use OnBoard, with sponsor-checked access to the OB process?  (there's no guarantee that the tenants will have an AD against which to check user credentials) -  I.e. depending on who approves your OB request determines what access policy you are assigned..?



  • 4.  RE: Can you partition the user database in ClearPass with different admin for each%3F

    EMPLOYEE
    Posted Oct 20, 2016 05:14 AM
    At first glance, that could work but it will be clunky. ClearPass isn't really designed to be truly multi-tenant from an admin standpoint.


  • 5.  RE: Can you partition the user database in ClearPass with different admin for each%3F

    EMPLOYEE
    Posted Oct 20, 2016 05:08 AM

    Not possible, though great idea.

     

    Similarly, the ability to restrict admin users to only see events/endpoints related to their particular services would be neat.  Sadly that is not possible also. :-(



  • 6.  RE: Can you partition the user database in ClearPass with different admin for each%3F

    Posted Oct 20, 2016 05:18 AM

    Many thanks for your reply too, Michael - glad to see you and Tim agree!