Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass with Cisco WLC for blocking applications and URLs

This thread has been viewed 9 times
  • 1.  ClearPass with Cisco WLC for blocking applications and URLs

    Posted Nov 30, 2019 11:10 PM

    Hi gurus,

     

    I know ClearPass and Cisco WLC can be integrated for 802.1X Role Based Access:

     

    https://community.arubanetworks.com/t5/Education-Australia-New-Zealand/Aruba-ClearPass-with-Cisco-WLC-802-1X-Role-Based-Access/gpm-p/455879

     

    With this, users can have access to different network segments according to the user's role.

    But, is possible to allow/deny access to differents applications and URLs according to the user's role? I believe ClearPass should reference a Cisco WLC's AVC profile, which in turn can control the recognized applications (drop, mark). Thanks in advance.

     

    Regards,

    Julián 



  • 2.  RE: ClearPass with Cisco WLC for blocking applications and URLs

    Posted Dec 01, 2019 07:50 PM

    Hi,

     

    It seems it can't be done. The Aruba ClearPass with Cisco WLC 802.1X Role Based Access post uses the Airespace-ACL-Name and the Airespace-Interface-Name attributes for referencing the ACL and VLAN respectively. But the Airespace RADIUS dictionary has no attributes which reference an AVC profile:

     

    airespace.PNG

    Then I think I can't block or allow applications according to the user role when using ClearPass along with Cisco WLC. Any ideas?

     

    Regards,

    Julián



  • 3.  RE: ClearPass with Cisco WLC for blocking applications and URLs

    Posted Dec 01, 2019 09:04 PM

    Did you try using av-pair and return avc-profile-name and role.

     

    Look at the bottom half of following link. I beleive it will work:

    https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/7-5/AVC_dg7point5.html



  • 4.  RE: ClearPass with Cisco WLC for blocking applications and URLs

    Posted Dec 01, 2019 09:19 PM

    Hi JayBee,

     

    Do you mean ClearPass return an attribute string "avc-profile-name" with value that matches "av-pair"?

     

    Regards,

    Julián



  • 5.  RE: ClearPass with Cisco WLC for blocking applications and URLs

    Posted Dec 01, 2019 09:26 PM

    Thats correct. Somthing like this:

    image.png

     

    And then on WLC, under Wireless-> Application Visibility and Control -> AVC profiles, try creating an AVC profile with a similar name and required policies.



  • 6.  RE: ClearPass with Cisco WLC for blocking applications and URLs

    Posted Dec 01, 2019 09:37 PM

    Ha, then it may work. I thought ClearPass doesn't have the Cisco-AVPair attribute, but actually it is in the Cisco RADIUS dictionary and not in the Airespace one.

    cisco_radius.PNG

    Thanks very much!

    Julián



  • 7.  RE: ClearPass with Cisco WLC for blocking applications and URLs

    Posted Dec 01, 2019 11:53 PM

    Try that and please let me know as well if it works.



  • 8.  RE: ClearPass with Cisco WLC for blocking applications and URLs

    Posted Dec 02, 2019 09:21 AM

    Yeah, I'll let you know. But because this is for a planned PoC I need to schedule and arrange all the requirements with customer, and it will take some time.

     

    Regards,

    Julián