- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
Passing Aruba-Device-Type from controller to CPPM
12-08-2014 11:30 AM
Is there a way to pass Aruba-Device-Type from a controller to CPPM? i.e. Controller indicates device type is Chromebook and passes that information to CPPM so it can make a decision. We're trying to ID chromebooks dynamically with MAC authentication (MAC in CPPM endpoint database). Is this possible?
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Passing Aruba-Device-Type from controller to CPPM
12-08-2014 11:31 AM
Yes, it is automatically included in the RADIUS request. You can reference it in the role map or enforcement using RADIUS:Aruba:Aruba-Device-Type
| Tim Cappalli | Aruba Security | @timcappalli | timcappalli.me |
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Passing Aruba-Device-Type from controller to CPPM
12-08-2014 11:33 AM
OK then that is the part that is broken I think. We do not see it in the input tab since the AOS upgrade. That is how it was set up before the AOS upgrade and it worked. Since AOS upgrade, it is no joy...
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Passing Aruba-Device-Type from controller to CPPM
12-08-2014 11:33 AM - edited 12-08-2014 11:35 AM
What code? I see it in 6.4.2.2
| Tim Cappalli | Aruba Security | @timcappalli | timcappalli.me |
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Passing Aruba-Device-Type from controller to CPPM
12-08-2014 11:40 AM
Opps, sorry.
AOS 6.3.1.13
CPPM 6.3.4.xxxx
We just upgrade the AOS code. We're hoping to upgrade CPPM version in a couple of weeks as we didn't want to change AOS & CPPM at the same time for troubleshooting reasons (if there was a problem).
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Passing Aruba-Device-Type from controller to CPPM
12-08-2014 11:41 AM
Are you seeing the device type in the user table?
| Tim Cappalli | Aruba Security | @timcappalli | timcappalli.me |
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Passing Aruba-Device-Type from controller to CPPM
12-08-2014 11:49 AM
Yes, I am seeing it there. It is also (as expected) showing up in the WebUI as well.
TAC just called and they are going to check on versioning information in regards to this situation. I swear it was working before the AOS upgrade but I'm old & forget things sometimes.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Passing Aruba-Device-Type from controller to CPPM
12-08-2014 12:08 PM
One other thing that you could possibly do is configure IF-MAP between the Aruba Controller and ClearPass, so that it passes that information from http user agent strings and mdns queries to clearpass from the device-type table of the controller: http://www.arubanetworks.com/techdocs/ArubaOS_63_Web_Help/Web_Help_Index.htm#ArubaFrameStyles/Management_Utilities/CPPM-ifmap.htm
*Answers and views expressed by me on this forum are my own and not necessarily the position of Aruba Networks or Hewlett Packard Enterprise.*
ArubaOS 8.5 User Guide
InstantOS 8.5 User Guide
Airheads Knowledgebase
Airheads Learning Videos
Aruba Central Documentation
Sign up for Security Alerts
Aruba Technical Webinars
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator
Re: Passing Aruba-Device-Type from controller to CPPM
12-08-2014 01:06 PM
I did a packet capture and radius is returning the fingerprint of the OS correctly to CPPM. CPPM is not dealing with it properly for some reason.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Alert a Moderator