Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

PaloAlto and CPPM 6.3.1 integration

This thread has been viewed 1 times
  • 1.  PaloAlto and CPPM 6.3.1 integration

    Posted Mar 27, 2014 05:05 PM

    Hi all, 

    I am trying to integrate Palo and CPPM. Unfortunately CPPM does not send any info to Palo. I see log-in/out at Palo however in the log from CPPM there is no <uid-message> and there are entries as follows: 

    [TIME Stamp] WARNING root pactrlmonitprofile Not sending userid object for padevice=[one  of my Palo's interfaces] as the data or auth_token is empty

     

    It seems that CPPM is misconfigured. Any ideas? 

    Many regards, 

     



  • 2.  RE: PaloAlto and CPPM 6.3.1 integration

    Posted Mar 27, 2014 05:09 PM

    Do you follow my TechNote describing the CPPM/PANW integration?



  • 3.  RE: PaloAlto and CPPM 6.3.1 integration

    Posted Mar 27, 2014 05:35 PM

    Absolutely, l did. Additionaly uou did not mention about enabling Userid per zone that is a key. The issue is at CPPM side I guess. 

    Many regards, 

     



  • 4.  RE: PaloAlto and CPPM 6.3.1 integration

    Posted Mar 27, 2014 06:31 PM

    OK  - Great, I know you have the basic covered.

     

    What version of PANW?

    What version of CPPM?

     

    You don't have multi-vsys do you?

    Nn 'funny' permit/deny rules in PANW stopping CPPM post the data to the PANW node?

     

     

    After a user associates to an ssid and you get the auth in CPPM, do you see in the access tracer for the user session an 'Accounting' Tab for the session?

     



  • 5.  RE: PaloAlto and CPPM 6.3.1 integration

    Posted Mar 27, 2014 08:05 PM

    Now I checked twice and found lack of Accounting at the controller. Now it looks fine! Thanks for tip.

    BTW, it was CPPM 6.3.1, PA-VM-6.0.0 and IAP 4.0.0.4 

     

    Many regards,

     

     

     



  • 6.  RE: PaloAlto and CPPM 6.3.1 integration

    Posted Mar 27, 2014 10:48 PM
    Great to hear..... Pretty sure I have checking the accounting on the Ctrls


  • 7.  RE: PaloAlto and CPPM 6.3.1 integration

    Posted Mar 28, 2014 02:30 PM

    Just wanted to ask.....

     

    Can you please expand on this "Additionaly uou did not mention about enabling Userid per zone that is a key"....??

     

     

    So I can add to my next CPPPM/PANW TechNote update.

     

    Cheers.