Security

last person joined: 22 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass and intune

This thread has been viewed 27 times
  • 1.  Clearpass and intune

    Posted Jul 10, 2019 06:27 AM

    Couple questions in the regards of CPPM and Intune extension.

    Sysinfo: CPPM 6.7.9, cluster of two nodes. Using intune extension v4.0.0.

     

    1) Any special considerations needed when deploying in a cluster?

    For now I ran all commands following the latest guides on the publisher, I assume this is the way, but a bit unsure in terms of the extension IP.

     

    2) Having the extension installed and added as an authorization source for the standard 802.1x CPPM service causes logins every so often to timeout.

    Access tracker reveals:

    Failed to get value for attributes=[OS Family].
    Session failed for Host=http://172.17.0.2, Reason=[get::<easy_perform>, (error=56) Failure when receiving data from the peer].
    [MS Intune Auth Source] - authorization took 30 secs

    Whenever the timeout doesn't happen I can see the gathered intune attributes.

     



  • 2.  RE: Clearpass and intune
    Best Answer

    EMPLOYEE
    Posted Jul 10, 2019 08:40 AM
    Did you install the extensions on all nodes in the cluster with the same IP?


  • 3.  RE: Clearpass and intune

    Posted Jul 10, 2019 10:34 AM

    Nopes, thought it was enough that the publisher node had the extension running. Setting it up on both nodes seem to have resolved it.



  • 4.  RE: Clearpass and intune

    Posted Nov 01, 2019 10:16 AM

    Should I be using the same IP on boths nodes of the cluster or choose a new one for the subscriber?

     

     



  • 5.  RE: Clearpass and intune

    Posted Dec 11, 2019 10:57 AM

    I want to echo BobC's question.  I have 7 subscribers that I need to configure for the Intune extension (publisher is already configured).  Do I use all of the same Azure information for the entire cluster (tenantID, ClientID, and clientSecret), as well as the same IP address?  Based on sharing a single auth source it would make sense that all 8 CPPM servers would use the same IP address.



  • 6.  RE: Clearpass and intune

    EMPLOYEE
    Posted Dec 11, 2019 01:50 PM

    The entire configuration should be the same on every node, including the extension IP.



  • 7.  RE: Clearpass and intune

    Posted Dec 11, 2019 02:55 PM

    Thanks Tim, our cluster configuration for Intune is complete.



  • 8.  RE: Clearpass and intune

    Posted Dec 12, 2019 12:03 PM