Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Change endpoint from portal

This thread has been viewed 0 times
  • 1.  Clearpass Change endpoint from portal

    Posted Sep 12, 2017 08:32 AM

    Hi!

     

    I´m trying to make a portal from wich users can register a device to the endpoint database and set a custom attribute I´ve created for devicetype.

     

    Similar to this but from a clearpass page: http://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/How-to-delete-modify-an-endpoint-attribute-using-tips-API/ta-p/246004

     

    I understand how to create endpoint attributes but not how to make a portal for my purpose.

     

    I´ve been looking at mactrac forms and messing around with them a bit. I gather that I will have to create somekind of custom field to be able to write changes to the endpoint database.

     

    The usage scenario is to selfregister devices and / or change the devicetype to get another type of network access for some users.



  • 2.  RE: Clearpass Change endpoint from portal

    EMPLOYEE
    Posted Sep 12, 2017 08:35 AM
    The device registration portal is designed for end user access and can be completely customized. The endpoints database in policy manager isn’t really designed for registration-like functionality.


  • 3.  RE: Clearpass Change endpoint from portal

    Posted Sep 12, 2017 08:43 AM

    Ok, so I cannot do this using the endpoint repository ?

    Can I achieve the same results using the device database ? As in make some devicecatogaries and other custom values for devices and change those from a portal ?



  • 4.  RE: Clearpass Change endpoint from portal

    EMPLOYEE
    Posted Sep 12, 2017 08:49 AM
    You could use the endpoint database, but it’s not recommended as it’s an administrative database, not an user facing database.

    The device registration portal is meant for end users and IT staff to “register” headless-type devices. You can have as many custom attributes as you want along with role, expiration, etc.


  • 5.  RE: Clearpass Change endpoint from portal

    Posted Sep 12, 2017 08:52 AM

    Ok, sounds like I should use the device registration portal. Got any good documentation on how to achieve what I´m talking about ?



  • 6.  RE: Clearpass Change endpoint from portal
    Best Answer

    EMPLOYEE
    Posted Sep 12, 2017 08:55 AM
    It’s something I’m working on but nothing to share quite yet. Please work with your Aruba ClearPass partner.


  • 7.  RE: Clearpass Change endpoint from portal

    Posted Sep 12, 2017 09:05 AM

    ok, I will check with them. Thanks for your answer.



  • 8.  RE: Clearpass Change endpoint from portal

    Posted Sep 12, 2017 09:26 AM

    oh , one last thing. Devices doesnt use guest licenses correct ?



  • 9.  RE: Clearpass Change endpoint from portal

    EMPLOYEE
    Posted Sep 12, 2017 09:28 AM

    Correct. No guest licenses are consumed for device registration.