Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Dynamic VLAN assingment in business center

This thread has been viewed 0 times
  • 1.  Dynamic VLAN assingment in business center

    Posted Mar 19, 2020 11:01 AM

    Hello, I am the owner of a business center. I have provided the property with network switches. It is the intention that several companies can settle in this building. Now my question is: is it possible that ClearPass can detect when company A plugs in a computer and when company B plugs in a computer. In this way, the correct VLANs can be assigned per company.

     

    It is possible that ClearPass is in the domain of the business center. This is independent of the other companies. 

     

    So clearpass should be able to differentiate between a number of different domains.

     

    Thanks!



  • 2.  RE: Dynamic VLAN assingment in business center

    MVP GURU
    Posted Mar 19, 2020 11:55 AM

    If you need to perform lookups for each businesses domains to see if a machine is owned/managed by their domain, ClearPass will need to be joined to of these domains. You will also need some sort of service account for ClearPass to be able to login to the domain controllers for user/device lookups.



  • 3.  RE: Dynamic VLAN assingment in business center

    Posted Mar 20, 2020 12:49 AM

    yes clearpass can do this 



  • 4.  RE: Dynamic VLAN assingment in business center

    Posted Mar 23, 2020 05:27 AM

    Hi, 

     

    Do you also know how to do this?



  • 5.  RE: Dynamic VLAN assingment in business center

    Posted Mar 23, 2020 06:15 AM

    Hi, 

     

    You mentioned that CPPM is in the domain of Business Center. How about different companies? will they be taking service from your DC? will you be running their domain services? if customer is running their domain services where will be their servers? 

     

    To be clear, if you want to check and differentiate company A from company B, the switches needs to be configured and integrated with Clearpass and Clearpass needs to be integrated with all these domains. You need to add your Clearpass to all these domains individually



  • 6.  RE: Dynamic VLAN assingment in business center

    Posted Mar 23, 2020 06:39 AM

    Hello

     

    I Created an diagram for clearity:

    Thebiestone_0-1584959537500.png

     

    Each company had is own servers connected with the swicthes from the business center. So they run their own services. 

     

    So for example: Laptop company A connect anywhere in the center with an switch port, CPPM should place this device automatically in VLAN 10.

    Same for laptop company B, if this device connect with switch he should placed in vlan 20 by CPPM. 

     

    So al switches are integrated as network device in clearpass. But how can clearpass join every domain? In the clearpass server administration you can only join 1 AD Domain...

     

    I hope its clear.

     



  • 7.  RE: Dynamic VLAN assingment in business center

    Posted Mar 23, 2020 07:12 AM
    Hi,

    Clearpass can join multiple domains simultaneously without any issues. Also
    i am not sure if there is any limitation on the number of ADs you can join.

    This is probably due to the fact that CPPM is basically joined as a
    computer in each of these domains and CPPM doesnt fetch and retain data
    from each of these domains. ( Yes there is cache which you can adjust
    accordingly)


  • 8.  RE: Dynamic VLAN assingment in business center

    Posted Mar 23, 2020 09:50 AM

    Hi

     

    Thanks i am going to try to add an second domain to it. Just then i need an central DNS server thats knows all the domains? Otherwise Clearpass cannot resolve the domains. I think?



  • 9.  RE: Dynamic VLAN assingment in business center

    Posted Mar 23, 2020 10:56 AM

    Hi, 

     

    Yes, you have to specify FQDN when adding the domain controller. IP is not accepted. Which implies you need to have a working DNS that is able to resolve all the domain controllers.