Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Enforcement Profiles and Device Group List

This thread has been viewed 8 times
  • 1.  Enforcement Profiles and Device Group List

    Posted Aug 25, 2017 12:28 AM

    Hi,

     

    Just wondering what the purpose of the Device Group List is when configuring Enforcement Profiles.

     

    How is the Device Group List used within a profile?

     

    Cheers



  • 2.  RE: Enforcement Profiles and Device Group List

    EMPLOYEE
    Posted Aug 25, 2017 12:31 AM
    If you assign a device group to a profile, you can return multiple enforcement profiles at the same time and ClearPass will send only the one that matches the source NAD.

    It's a niche feature for some unique use cases and isn't commonly used.


  • 3.  RE: Enforcement Profiles and Device Group List

    Posted Aug 25, 2017 12:43 AM

    When you "you can return multiple enforcement profiles at the same time" what exactly do me mean?

    Do you mean that a single client request can be answered with multiple enforcemnt profiles? Or that he enforcement profile will be sent out to multiple devices contained with the device list?

     

    What would be a situation where you would want to do something like this?



  • 4.  RE: Enforcement Profiles and Device Group List
    Best Answer

    EMPLOYEE
    Posted Aug 25, 2017 12:47 AM
    In your policy, you could specify multiple enforcement profiles and ClearPass would send he correct one to the NAD based on the source of the request.

    For example, using a single service for multiple vendors (I personally wouldn't recommend this).



    TIM CAPPALLI

    Aruba Security


  • 5.  RE: Enforcement Profiles and Device Group List

    Posted Aug 25, 2017 08:03 AM

    I appreciate you taking the time the explain in more detail.

    I think I understand what you are saying.

     

    Good to know what it is for. I don't have a user for it, but good to know what it is there for.

     

    Cheers



  • 6.  RE: Enforcement Profiles and Device Group List

    Posted Mar 16, 2018 09:41 PM
    Hi
    For this that you said can you show us a config example please.
    I need to add to my clearpass two aruba controller as nad, i know how make he group list, but i don`t know how to apply to the enforcement profile and then to the enforcement policy for.my service.

    I had to confiure two service, one for each controller (nad)


  • 7.  RE: Enforcement Profiles and Device Group List

    Posted Oct 17, 2019 02:20 PM

    An appropriate use of this feature might be for Palo Alto where the return information is different for Firewalls and Panorama.