Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass VM redundancy

This thread has been viewed 6 times
  • 1.  Clearpass VM redundancy

    Posted Jul 24, 2014 02:46 AM

    If a customer who has purchased a single VM instance of ClearPass wants to address the issue of redundancy by taking a snapshot of the installed and configured machine - will there be any issues experienced when the snapshot is brought up on a different piece of hardware. The scenario might be two separate datacentres, I am worried about the license still being valid etc.



  • 2.  RE: Clearpass VM redundancy

    Posted Jul 24, 2014 09:15 AM

    I have a very similar problem. We cannot afford to buy two clearpass licenses.  We have a VMware setup with High Availability.  With regular backups/snapshots to guard against software issues, and VMotion to move the VM to another server if neccessary do we really need redundant Clearpass VMs?



  • 3.  RE: Clearpass VM redundancy

    EMPLOYEE
    Posted Jul 24, 2014 10:17 AM
    While this may work, what would you during the during the time the restore or migration? Network authentications would not be able to happen. This is why two VM's are required for HA.


  • 4.  RE: Clearpass VM redundancy

    Posted Jul 24, 2014 10:41 AM

    Currently we would be using ClearPass for just wireless.  To our instituion wireless is still a "nice to have" not mission critical.  If we went down for minutes/hours it would be an inconvience.

     

    When we start using ClearPass as our NAC for wired and wireless we will be forced to run a second ClearPassVM as then it would be a necessity.

     

    I guess my question is more along the lines of "Does clearpass require two instances to run or can it run as a single unit?"

    and it appears the answer is yes, but it's not best practice.

     

     



  • 5.  RE: Clearpass VM redundancy

    EMPLOYEE
    Posted Jul 24, 2014 10:44 AM
    Yes, you can run with one instance.


  • 6.  RE: Clearpass VM redundancy

    Posted Jul 29, 2014 10:41 AM

    Besides automated failover.  Is there any features we would be missing if we only ran a single instance of ClearPass?