Security

Reply
Occasional Contributor II

ClearPass AV/AS software update

Hi everyone!!!

 

After the worldwide problem suffered today with the automatic update of the AV/AS which has stoped the Policy Manager till Aruba has released a fix using the same way, is there any way to stop receiving updates but going on having the choice to download new versions?

 

I have been asked to be able to download newer versions but deny the updates from the Posture & Profile Data Updates...

 

Have been checking all the features but none has been found.

 

Thx in advanced!!! :)

 

JoseMi

JoseMi Cruz
Guru Elite

Re: ClearPass AV/AS software update

Remove the subscription ID. When you want to do an update/upgrade, add it back and check for updates.

| Tim Cappalli | Aruba Security | @timcappalli | timcappalli.me |

NOTE: Answers and views expressed by me on this forum are my own and not necessarily the position of Aruba or Hewlett Packard Enterprise.
Occasional Contributor II

Re: ClearPass AV/AS software update

It does not ensure that CPPM will not download and install newer versions of the Posture & Profile Data Updates as it does it by itself every hour when I fill with the ID again.

 

I have received a notification from Aruba this morning early where we can read this:

 

"Can we prevent this in the future by blocking any automatic push to our environment?

Ans.        By default, all ClearPass appliances will download Posture & Profile Data Updates automatically.  At this time, there is no configurable option to selectively opt-out of these downloads.  We are investigating what options we may provide to customer so they have this ability to selectively opt-in or opt-out."

 

So, we have only two ways to isolate the CPPM AV/AS updates from Internet, whether to remove the subscription ID (as you said) or (in my case) the proxy configuration. Using one of these methods will prevent CPPM from install a wrong version but keep in mind that also the Firmware and Patch Updates part will not reach the Internet.

JoseMi Cruz
Guru Elite

Re: ClearPass AV/AS software update

You can download software updates offline and import them without adding the subscription ID back.

| Tim Cappalli | Aruba Security | @timcappalli | timcappalli.me |

NOTE: Answers and views expressed by me on this forum are my own and not necessarily the position of Aruba or Hewlett Packard Enterprise.
Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: