Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all
This thread has been viewed 9 times
  • 1.  NAC

    Posted Jun 06, 2014 10:13 AM

    Hi Team,

     

    what are the requirements that must be considered to implement "NAC" on a network?

     

    What are the steps to implement ONGUARD with cisco switches?

     

    Please a need help me

     

    Regards,

     



  • 2.  RE: NAC
    Best Answer

    EMPLOYEE
    Posted Jun 06, 2014 10:17 AM

    OnGuard is only available for desktop operating systems (Windows, OS X, Linux).

     

    Implementation is relatively simple.

     

    At a high level:

     

    In ClearPass, you configure the posture policies by operating system. These can include:

       - Firewall enforcement

       - Antivirus enforcement

       - Installed application enforcement

     

    If the device does not have OnGuard installed, ClearPass tells the Cisco switch to redirect the user to the install page.

     

    Once OnGuard is installed, it communicates with ClearPass directly to inform about posture changes. If the device goes out of compliance, ClearPass can trigger the switch to bump the user and redirect them to a quarantine VLAN.

     

     



  • 3.  RE: NAC

    Posted Jun 06, 2014 10:24 AM

    Hi,

     

    cappalli, 

     

    In the configuration the ClearPass in the service.

     

    First is user authentication?

       For example 802.1x

    And then the verification of compliance?

     

    Regards,

     

     



  • 4.  RE: NAC

    EMPLOYEE
    Posted Jun 06, 2014 10:41 AM
    Correct. If a client doesn't have OnGuard installed, they'll usually get the "Unknown" posture token. In your 802.1X authorization, you can say:

    If TIPS POSTURE EQUALS Unknown
    Return a quarantine VLAN and Cisco redirect URL.


  • 5.  RE: NAC

    Posted Jun 06, 2014 10:47 AM

    Hi.

     

    Perfect.

     

    When using 802.1x (WIRED). That is advisable to use authentication?

     

    Regards,



  • 6.  RE: NAC

    EMPLOYEE
    Posted Jun 06, 2014 10:48 AM

    You can use MAC-Auth or 802.1X on the wire. 802.1X would be the most secure.



  • 7.  RE: NAC

    Posted Jun 06, 2014 10:52 AM

    Ok,

     

    If a guest user should then use MAC authentication and not use agent.

     

    Regards,



  • 8.  RE: NAC

    EMPLOYEE
    Posted Jun 06, 2014 10:56 AM

    You could have a guest user use the dissolvable web agent if you wanted.



  • 9.  RE: NAC

    Posted Jun 06, 2014 10:58 AM

    Hi,

     

    Perfect. I thank you for the support. It has been very helpful

     

    Regards,



  • 10.  RE: NAC

    Posted Jun 06, 2014 12:13 PM

    Sorry Tim,

     

    What is the redirect to the ENFORCEMENT PROFILE set to cisco

     

    Regards,



  • 11.  RE: NAC

    EMPLOYEE
    Posted Jun 06, 2014 12:23 PM

    Try something like this (you'll need to build the web page).

     

    wired-cisco-onguard-redirect.PNG



  • 12.  RE: NAC

    Posted Jun 06, 2014 12:26 PM

    Thanks Tim.

     

    Thanks very much :smileyvery-happy: