Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Headless onbording in ClearPass

This thread has been viewed 6 times
  • 1.  Headless onbording in ClearPass

    Posted Feb 21, 2019 05:27 AM

    Hi,

     

    Given that we have applied 802.1x on wired network, there are issues with devices that do no support it.

    As we are an university, we have many different types of users (administrative staff, researchers, students etc) and even more weird devices.

     

    My idea of a flow for onboarding is:

    1. User connects the device to wired network.
    2. Device will be redirected to guest registration, but will have no effect, as it's a headless device. A dhcp packet is forwarded to ClearPass, hence it is now profiled.
    3. User logs into a self service page I will develop. User can lookup the mac address and take ownership of the specific device.
    4. When device is reconnected, it will Mac AUTH and be placed in a vlan dedicated for this kind of device.

    Step 1-3 is no problem, but I have a problem in step 4.

    My plan is in step 3 to add the attribute "Owner" to the device, and enter the username of the person who has taken ownership of the device.

    What i need now, is to configure Clearpass to do Mac Auth and use the device attribute "owner" to lookup in AD to see if that user exists. If i can also check if the user is active and not disable in AD, it would be great, but not nessesary.

     

    Does anone have some sort of input on how to achieve this?

     

    Br,

    Thomas 



  • 2.  RE: Headless onbording in ClearPass

    EMPLOYEE
    Posted Feb 21, 2019 05:49 AM
    Onboarding in ClearPass means certificate issuance. Sounds like you just want to register them. Why not just use the built-in Device Registration portal vs building something custom?


  • 3.  RE: Headless onbording in ClearPass

    Posted Feb 21, 2019 06:20 AM

    Hi,

     

    That is quite possible what I could need.

    Do you by any chance have some pointers in how to get started with Device Registration portal?

     

    Br,

    Thomas



  • 4.  RE: Headless onbording in ClearPass

    Posted Feb 21, 2019 06:24 AM

    Hi again,

     

    I may have answered a bit to quick.

    I want to register headless devices. Meaning the device itself have no display and therefor cannot access a regstration page.

     

    This is why i wanted a page for registrating the specific device/mac address. This should be done from a computer ot the like.

     

    Br,

    Thomas



  • 5.  RE: Headless onbording in ClearPass
    Best Answer

    EMPLOYEE
    Posted Feb 21, 2019 07:03 AM
    That is exactly how it's built. It has a basic setup out of the box (in Guest go to Create Device) and it can be completely customized.


  • 6.  RE: Headless onbording in ClearPass

    Posted Mar 04, 2019 03:44 PM

    I found ti was easy to setup the devices.

    However, i do no appreciate the interface for my users, and it does not fit our current strategy, so I will make a webinterface afterall.

    But now i know where to add them and make then authenticate. :)

     

    Br,

    Thomas



  • 7.  RE: Headless onbording in ClearPass

    EMPLOYEE
    Posted Mar 04, 2019 03:54 PM
    The interface can be completely customized by user group.


  • 8.  RE: Headless onbording in ClearPass

    Posted Mar 04, 2019 03:58 PM

    Yes, but they want it as an integrated part of a selfservice portal.

    And for the time being, it's easier for them to develop it themselves.

     

    If we get my other issue sorted with the API.. :) Different thread.

     

    Thanks for the help. I was barking up the very wrong tree as i though i was suppoed to work in endpoints instead of devices. :)

     

    Br,

    Thomas



  • 9.  RE: Headless onbording in ClearPass

    Posted Feb 28, 2019 12:54 PM

    You can start off by registering devices via /tips in the ClearPass. Just open Guest and look for Manage Devices.

    2019-02-28_12h47_19.png

    Then in your service, just make sure you include the authentication source [Guest Device Repository].

     

    I set this up in my environment based on the suggestion from Tim and it worked like a champ.

     

    Once you have the device authenticating properly, you just need to map a service to the profile for Device Registration and you'll be able to delegate the task to whoever you want.