Security

last person joined: 18 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Is it possible to edit the ClearPass's host file?

This thread has been viewed 1 times
  • 1.  Is it possible to edit the ClearPass's host file?

    Posted Oct 13, 2015 06:02 AM

    Dear Community,

     

    Our customer doesn't want to set dns-server IP in ClearPass, because they separate the CP's VM in their network and they won't let the CP access to the DNS-server. They would like to edit the host file instead. Is it possible?

    Thank you for your answer in advance!

     



  • 2.  RE: Is it possible to edit the ClearPass's host file?

    Posted Oct 13, 2015 07:22 AM
    I am pretty certain that all access to ClearPass OS system files requires A support case and I am not sure they would support manual edits to the hosts file. When we configure a ClearPass box for a guest network we will usually use DNS proxy (goes by many names depending on the FW manufacturer) to respond with the internal/DMZ addresses where needed and forward the rest out to a public DNS.


  • 3.  RE: Is it possible to edit the ClearPass's host file?
    Best Answer

    EMPLOYEE
    Posted Oct 13, 2015 09:51 AM

    @Zsomi wrote:

    Dear Community,

     

    Our customer doesn't want to set dns-server IP in ClearPass, because they separate the CP's VM in their network and they won't let the CP access to the DNS-server. They would like to edit the host file instead. Is it possible?

    Thank you for your answer in advance!

     


    The short answer is No.  CP should be on the side of the "firewall" that allows it to access DNS as well as domain controllers, because if you use 802.1x DNS will be used to discover domain controllers for authentication.  If your clearpass box cannot access DNS, please re-consider how you are designing your network.



  • 4.  RE: Is it possible to edit the ClearPass's host file?

    Posted Oct 13, 2015 10:02 AM

    Dear cjoseph,

     

    Thank you for your reply. We also suggested to use DNS-server, but they wanted to know is it possible to edit the hostfile. Thank you again.