Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass OnGuard - switch requirements

This thread has been viewed 9 times
  • 1.  ClearPass OnGuard - switch requirements

    Posted Aug 21, 2012 06:37 PM

    Is there a list of supported switches that work with ClearPass OnGuard? Or is there a list of required features that the switch has to support in order to provide full OnGuard functionality?

     

    thanks,



  • 2.  RE: ClearPass OnGuard - switch requirements

    Posted Aug 22, 2012 09:01 PM

    The primary requirement when it comes to a switch is dot1x support.  Check your switch model documentation and look for the ability to configure a RADIUS server using aaa and dot1x commands.  Different switches will provide differnt levels of richness when it comes to the dot1x.  E.g. can you pass back just a simple vlan vs. a role name vs. a dynamix ACL etc. etc. 

     

    You should check with your local account team for more information.



  • 3.  RE: ClearPass OnGuard - switch requirements

    Posted Jun 05, 2013 08:49 PM
    We asked for this and basically got the exact information that cisco ISE has listed. We have cisco wired. Do you have OnGuard working in an 802.1x environment. Curious how you handle this on wired including how OnGuard agent is deployed.


  • 4.  RE: ClearPass OnGuard - switch requirements

    Posted Jul 29, 2013 07:39 PM

    i'll throw my name against this as well, i'm finding it very hard to work out what to do here.



  • 5.  RE: ClearPass OnGuard - switch requirements

    Posted Jul 29, 2013 08:41 PM
    Just curious what your trying to do on the wired side?


  • 6.  RE: ClearPass OnGuard - switch requirements

    Posted Jul 29, 2013 08:59 PM

    802.1x with 3750's and using the Onguard client to manage a quarantine VLAN.

     

     



  • 7.  RE: ClearPass OnGuard - switch requirements

    Posted Jul 29, 2013 09:02 PM
    We are hoping to get dot1x going. Our environment should be interesting as we have some switches that are 10years old. We have some 3750s too. So you went vlan switching as opposed to L3 ACLs?


  • 8.  RE: ClearPass OnGuard - switch requirements

    Posted Aug 04, 2013 10:12 PM

    haven't really decided on the overal solution yet, only just got the dot1x working with the NAP agent on Windows.

     

    As it happens it doesn't look like you can use the onguard agent in an 802.1x installation. only microsoft NAP.

     



  • 9.  RE: ClearPass OnGuard - switch requirements

    Posted Aug 06, 2013 10:07 AM

    @scottdoorey wrote:

    As it happens it doesn't look like you can use the onguard agent in an 802.1x installation. only microsoft NAP.

     


    i used onguard agent (permanent one, not disolvable) fine with 802.1x wired and wireless. went for the dynamic vlan route, not optimal as clients don't like being thrown in a different VLAN (keep there DHCP address), but with a NIC bounce (via the agent) it worked well enough.



  • 10.  RE: ClearPass OnGuard - switch requirements

    Posted Aug 06, 2013 05:06 PM

    service1.jpgservice1.jpghow do you tie the Onguard Posture policy in with the 802.1x posture policy?

     

    When i setup an 802.1x service, it only allows me to select Microsoft NAP options.

     

    posture 2.jpg



  • 11.  RE: ClearPass OnGuard - switch requirements

    EMPLOYEE
    Posted Aug 06, 2013 05:30 PM

    When setting up onguard you are going to have 2 services. 

     

    1. 802.1x (radius service)

    1. OnGuard (webauth service)

     

    onguard2.png

     

    You will need to have in your enforcement profile to look for posture tokens

     

    onguard3.png

     

     

    Its not an easy process to do on your own the first time, so I always recommend that you work with your local SE or Clearpass SE.



  • 12.  RE: ClearPass OnGuard - switch requirements

    Posted Aug 06, 2013 06:10 PM
    So the enforcement profile in the dot1x service checks for posture tokens created by the Onguard service ?

    The windows NAP agent just seems a little more elegant.

    Sent from my iPhone


  • 13.  RE: ClearPass OnGuard - switch requirements

    EMPLOYEE
    Posted Aug 06, 2013 06:19 PM
    It maybe a little easier but NAP is very limited on what you can check


  • 14.  RE: ClearPass OnGuard - switch requirements

    EMPLOYEE
    Posted Aug 06, 2013 06:33 PM

    If you are only checking windows devices NAP is the easiest way of doing it but If you want to check advance settings (reg keys, etc) MAC you will need to use the onguard agent. 

     

    http://www.arubanetworks.com/pdf/products/DS_ClearPass_OnGuard.pdf

     

    onguard4.png



  • 15.  RE: ClearPass OnGuard - switch requirements

    Posted Aug 07, 2013 02:42 AM

    yeah that detail escaped me, once i got used to it it felt "normal". as we were dealing with MacOS systems also Microsoft NAP was never an option.

     

    the agent service provides the posture and the 802.1x wired service uses that posture token.

     

    the problem is that you need IP connectivity for the onguard agent to communicate with the CPPM, only microsoft NAP is able to send data through the 802.1x process. would be nice if Aruba could pull that off also with the OnGuard agent :)



  • 16.  RE: ClearPass OnGuard - switch requirements

    Posted Aug 07, 2013 08:00 PM

    ok, now i get it.

     

    I think i've got it working in this fashion however i'm not sure about dynamically reauthorising the user on dot1x after the web auth has been done.

     

    Is this simply a case of sending a bounce client message to the NAS then the having the "cache posture from previous sessions" enabled in the dot1x service?

     

    scott



  • 17.  RE: ClearPass OnGuard - switch requirements

    EMPLOYEE
    Posted Aug 07, 2013 08:08 PM
    correct


  • 18.  RE: ClearPass OnGuard - switch requirements

    Posted Aug 07, 2013 08:10 PM

    ok great, feeling much better about this now! Thanks for your help Troy.

     

    Unfortunately our local SE's weren't fully up to speed on the Onguard stuff so i've been trying to work it out the hard way!

     

    scott



  • 19.  RE: ClearPass OnGuard - switch requirements

    Posted Aug 04, 2013 10:23 PM
    Nice. May I ask if you had to have another server for Microsoft NAP or just the clearpass sever?


  • 20.  RE: ClearPass OnGuard - switch requirements

    EMPLOYEE
    Posted Aug 06, 2013 02:41 AM

    scottdoorey,

    What are you trying to accomplish that you say you can use OnGuard in a .1x environment? I have multiple customers that have OnGuard installed with .1x and its one of the items you are taught how to use in the partner workshops.


    Again I know this is a hot topic for everyone out there and we are hoping to have a document soon for public use on how to use on guard. There are a few examples in the CPPM server you just need to click the help link in the top right corner and search for posture.

     

    posture.png