Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Endpoint Profiler DHCP don't work

This thread has been viewed 6 times
  • 1.  Endpoint Profiler DHCP don't work

    Posted Feb 12, 2019 09:57 PM

    Dear

    I have a network that I have configured an ArubaOS8.3 controller, clearpass 6.7 with policies to ensure that only mobile devices connect to the 802.1x network, but even configured relay on the Core switch on the lan specifies pointing to the Clearpass, does not receive the IP of dhcp, however device classification works through the DHCP fingerprint.
    Now it usually authenticates in clearpass but does not receive IP.
    In the controller the IP receives the IP correctly, but this same IP is not received in the user who authenticates in the clearpass. DHCP is running normally on the client.



  • 2.  RE: Endpoint Profiler DHCP don't work

    Posted Feb 12, 2019 10:15 PM

    Have you enabled "Profile Endpoints" in your ClearPass service? And In the profile tab, select any category/any OS



  • 3.  RE: Endpoint Profiler DHCP don't work

    Posted Feb 13, 2019 06:19 AM

    Yes I have.

     

    Sevices 1.PNGservices 2.PNGservices 3.PNGAccess Tracker.PNGaccess tracker endpoint.PNG



  • 4.  RE: Endpoint Profiler DHCP don't work

    Posted Feb 13, 2019 08:55 AM
    Don’t quite understand your issue , are you able to see that ClearPass was able to profiled and categorized the device (s) under the endpoint db ?

    Or you are concern that the ip address reflected under the endpoint db doesn’t match the assigned IP on the device itself?

    Sent from Mail for Windows 10


  • 5.  RE: Endpoint Profiler DHCP don't work

    Posted Feb 13, 2019 09:46 AM

    As for the Endpoint, I believe that it is categorizing correctly according to the images below, but it is not able to assign IP of this VLAN, not even in the controller can get the IP.endpoint1.PNGendpoint2.PNGendpoint3.PNGendpoint4.PNGendpoint 5.PNG



  • 6.  RE: Endpoint Profiler DHCP don't work

    Posted Feb 13, 2019 12:30 PM
    Look in access tracker and make sure you are returning the correct user-role from ClearPass and if the correct user-role is being sent then verify that are using the necessary ACLs under the user-role

    You can run the show user-role | include to validate what role the device is getting

    Then run the show rights to see the level of access under the device role


    Thank you

    Victor Fabian

    Pardon typos sent from Mobile


  • 7.  RE: Endpoint Profiler DHCP don't work

    Posted Feb 13, 2019 01:15 PM
      |   view attached

    See the commands on the controller

    Attachment(s)

    txt
    putty.txt   10 KB 1 version


  • 8.  RE: Endpoint Profiler DHCP don't work

    Posted Feb 15, 2019 09:02 AM

    any idea how to solve it?



  • 9.  RE: Endpoint Profiler DHCP don't work

    EMPLOYEE
    Posted Feb 15, 2019 09:18 AM

    As victor suggested have you checked the profile CPPM is sending to Controller and role client is receving in access tracker? If this detials are correct then I would recommand to file AOS tac ticket.

     



  • 10.  RE: Endpoint Profiler DHCP don't work

    Posted Feb 20, 2019 07:04 AM

    No Yet . I opened a TAC but it still has not been resolved.