Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Entry license profiling and endpoint attributes

This thread has been viewed 4 times
  • 1.  Entry license profiling and endpoint attributes

    Posted Apr 03, 2020 09:40 AM

    Hi, with Clearpass Entry license, profiling shouldn't be available. However, I've installed a CPPM with Entry license and I see the endpoints getting profiled and it's even possible to use profiling in services. Is this a functionaltiy that is yet to be dropped in a new sw version? I would like to know what endpoint attributes we would be able to use in the policy rules.



  • 2.  RE: Entry license profiling and endpoint attributes

    MVP GURU
    Posted Apr 03, 2020 09:56 AM

    True, entry should not allow TACACs, profiling, or 3rd party integration. Do you have some evaluation/demo licenses still active? 

     

     



  • 3.  RE: Entry license profiling and endpoint attributes

    MVP GURU
    Posted Apr 03, 2020 09:57 AM

    I also suppose you are at least on version 6.8 ?

     

     



  • 4.  RE: Entry license profiling and endpoint attributes

    Posted Apr 03, 2020 10:06 AM

    Yes, v 6.8. It's an Entry evaluation license. I have to make a services design, but I don't know which attributes will be available with Entry. That's why I installed this eval on a new test server. But I don't see any difference with Access licenses at the moment.



  • 5.  RE: Entry license profiling and endpoint attributes

    MVP GURU
    Posted Apr 03, 2020 10:12 AM

    Do you have any other licenses active on the server? Is it using an Access license? Is this server part of a cluster that has Access licensing?



  • 6.  RE: Entry license profiling and endpoint attributes

    Posted Apr 03, 2020 10:37 AM

    Hi, no it's a new standalone eval server (VM) with only an eval platform license and eval Entry license.

     

    Did you already install an Entry-licensed CPPM? I'd like to see how the endpoint entries look like and what is available for policy rules.



  • 7.  RE: Entry license profiling and endpoint attributes

    Posted Apr 05, 2020 05:08 AM

    Did anyone actually install an Entry-licensed CPPM?



  • 8.  RE: Entry license profiling and endpoint attributes

    MVP GURU
    Posted Apr 05, 2020 10:18 AM

    I have. And it works as advertised. You will get low level system profile information, but no full profiling. TACACS is not available, and I was not able to add an external context server. 

     

    Maybe re-install the VM, and migrate the licenses over to it?

     

    Also make sure to double check that you do not have any type of evaluation licenses installed when you begin testing.

     

     



  • 9.  RE: Entry license profiling and endpoint attributes

    Posted Apr 05, 2020 12:43 PM

    Ah ok nice. I installed a fresh CPPM with Entry eval only. Maybe eval Entry license are more like Access Licenses.

    How do the endpoint entries look like? Do they have less fields or are the simply not fingerprinted automatically?



  • 10.  RE: Entry license profiling and endpoint attributes
    Best Answer

    MVP GURU
    Posted Apr 06, 2020 02:38 PM

    The endpoints are not profiled, and will have basic information. See the attached images for what my iPad looks like, even with profiling configured correctly.

     

     



  • 11.  RE: Entry license profiling and endpoint attributes

    Posted Apr 07, 2020 03:05 AM

    Thx Dustin. That's helpful info. I can confirm that with the eval version at this moment al functions are available, even without access or entry licenses. Apparently 100 access licenses are included with the eval platform key.



  • 12.  RE: Entry license profiling and endpoint attributes

    MVP GURU
    Posted Apr 06, 2020 02:39 PM

    And also to your last comment, the Entry licenses are like a basic version of Access licenses. There is also a special part number to upgrade from entry to access licenses.