Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Easy way to add attributes to the Endpoint database from Mac_create form

This thread has been viewed 2 times
  • 1.  Easy way to add attributes to the Endpoint database from Mac_create form

    Posted Jun 17, 2020 09:56 PM

    Does anyone have a way to add attributes from the Mac_create form?  I know that the attributes are added in the guest device repository but would like to see in the endpoint repository. 

     

     

    Thanks in advance.



  • 2.  RE: Easy way to add attributes to the Endpoint database from Mac_create form

    Posted Jun 17, 2020 10:46 PM
    You are trying to add attribute to the endpoint db when the device is registered via the GDR form?



    Thank you

    Victor Fabian

    Pardon typos sent from Mobile


  • 3.  RE: Easy way to add attributes to the Endpoint database from Mac_create form

    Posted Jun 17, 2020 10:52 PM

    Yes, Victor.   We want to be able to see the attribute in the main endpoint database so the admins don't have to look at the guest device repository.



  • 4.  RE: Easy way to add attributes to the Endpoint database from Mac_create form
    Best Answer

    EMPLOYEE
    Posted Jun 18, 2020 05:57 AM

    What you could do is on every authentication Update Endpoint attributes for the fields you are interested in, to the values that came from the Guest Device/User database. You will see the attributes then after the first authentication in the Endpoint Repository.



  • 5.  RE: Easy way to add attributes to the Endpoint database from Mac_create form
    Best Answer

    Posted Jun 18, 2020 06:54 AM
    You can add a “change of authorization” field to the mac_create form and when the user Submits the form, it will automatically execute a CoA and use the device disconnect service (you will need to copy the service to make any modifications).
    In the enforcement policy of device disconnect service , you can can add the custom endpoint attribute



    Thank you

    Victor Fabian

    Pardon typos sent from Mobile


  • 6.  RE: Easy way to add attributes to the Endpoint database from Mac_create form

    MVP EXPERT
    Posted Jun 18, 2020 10:36 AM

    You should not do this as the data does not sync when changed. Just get the value from GDR authorization source.

     

    Endpoint Database is meant for machine data, not user entered.