Security

last person joined: 23 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

How to Build Policy Simulation for Service Categorization

This thread has been viewed 0 times
  • 1.  How to Build Policy Simulation for Service Categorization

    Posted Dec 17, 2014 10:04 PM
      |   view attached

    I am attampting to use the Policy Simulation to build a Serivce Categorization.  Attached is my simulation, but it doesn't seem to match a valid service I have running. I am attaching the screenshot and policy simulation file.

     

    Are there any docs or examples of how to build a simulation and test it against a service?



  • 2.  RE: How to Build Policy Simulation for Service Categorization

    EMPLOYEE
    Posted Dec 17, 2014 10:06 PM

    Can you confirm that some of those attributes are present as service rules in an active service?



  • 3.  RE: How to Build Policy Simulation for Service Categorization

    Posted Dec 17, 2014 10:11 PM
      |   view attached

    Tim,

     

    I am learning ClearPass, so be gentle as I am likely missing something obvious.  Total NOOB here. I took a working Wired 802.1x service and looked in Access Tracker to see a valid request that came in and tried to replicate those Radius reqeust attributes in the policy simulation.  Is that a valid way to go about building a simulation?  Attached is the Wired service I built the policy from.

     

     

    Attachment(s)

    txt
    WiredService.xml.txt   19 KB 1 version


  • 4.  RE: How to Build Policy Simulation for Service Categorization

    EMPLOYEE
    Posted Dec 17, 2014 10:15 PM

    Hm. The service rules look correct.

     

    Are you working with an Aruba partner? It looks like this is a proof of concept build.



  • 5.  RE: How to Build Policy Simulation for Service Categorization

    Posted Dec 17, 2014 10:17 PM

    I am working with Aruba directly as we are testing the product and trying to get familiar with its capabilities.  The Policy Simulation was intriguing if I can get it working.



  • 6.  RE: How to Build Policy Simulation for Service Categorization

    EMPLOYEE
    Posted Dec 17, 2014 10:38 PM

    Can you try creating a simulation with just the basics:

     

    NAS Type: Generic

    Authentication outer method PEAP

    Username

    Password

    IETF NAS-Port-Type 15



  • 7.  RE: How to Build Policy Simulation for Service Categorization

    Posted Dec 17, 2014 10:52 PM
      |   view attached

    Thanks for your help Tim.  Not sure I am doing this right.  I have attached the simulation I built for your review. 

     

    Couple of Questions if I may:

     

    1.  Does the order of attributes in the RADIUS request matter?

    2.  Where is NAS Type Generic?  I didn't see where to select that attribute?

    Attachment(s)

    txt
    SimulationV3.xml.txt   1 KB 1 version


  • 8.  RE: How to Build Policy Simulation for Service Categorization
    Best Answer

    EMPLOYEE
    Posted Dec 18, 2014 12:50 AM

    You must add a connection Type in the test.

     

    Mark,

     

    I updated my lab on your test. You can see the results there. I aslo trigger my services based on NAS IP so you also need to add the IP of the switch. 

     

    Screen Shot 2014-12-17 at 11.47.37 PM.png



  • 9.  RE: How to Build Policy Simulation for Service Categorization

    Posted Dec 18, 2014 07:31 AM

    Thanks Troy.  That was the missing piece.



  • 10.  RE: How to Build Policy Simulation for Service Categorization

    Posted Dec 17, 2014 10:06 PM
      |   view attached

    Here is the attached simulation file.

    Attachment(s)

    txt
    Simulation.xml.txt   1 KB 1 version