Security

last person joined: 2 days ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass: how to set an Endpoint Attribute value based on another attribute value

This thread has been viewed 13 times
  • 1.  ClearPass: how to set an Endpoint Attribute value based on another attribute value

    EMPLOYEE
    Posted Oct 17, 2019 12:58 PM

    Hi Airheads!

     

    I am trying to create a Post-Auth Enforcement Profile that sets a custom Endpoint Attribute value based on the value of another attribute in the Endpoint Repository. Basically, I am trying to map the Endpoint Repository "Hostname" value into a custom Endpoint Attribute called "Hostname" so I can reference it in an LDAP query.

    The problem is that I don't know the correct syntax to do that. I've tried several iterations along these lines:

    Enforcement Profile.JPG

    However, this simply returns my query as text into the attribute:Endpoint Attributes.JPG

    Does anyone know how to do this?

     

    Cheers,

    Chris



  • 2.  RE: ClearPass: how to set an Endpoint Attribute value based on another attribute value

    Posted Oct 22, 2019 08:47 AM

    I think you're looking for :

     

    %{Authorization:[Endpoints Repository]:Hostname}



  • 3.  RE: ClearPass: how to set an Endpoint Attribute value based on another attribute value

    EMPLOYEE
    Posted Oct 22, 2019 12:17 PM
    Thanks rkerr, I tired that query as well, and it only returns the query text in the attribute, not the queried value. I'm working with the TAC to get an answer, if they figure it out I will post their solution.


  • 4.  RE: ClearPass: how to set an Endpoint Attribute value based on another attribute value

    Posted Oct 22, 2019 12:29 PM

    It works fine for me - is the Endpoint Repository definitely selected as an Authentication Source in the service definition?



  • 5.  RE: ClearPass: how to set an Endpoint Attribute value based on another attribute value

    Posted Oct 22, 2019 02:12 PM

    You must see the value in the access tracker, if you se it there, then the correct autorisation source is enabled, en you can use it in a post authenication and write it to an endpoint.