Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Posture Policy Enhancements

This thread has been viewed 4 times
  • 1.  Posture Policy Enhancements

    Posted Mar 31, 2014 11:24 AM
      |   view attached

    Ciao,

    about the possibility to configure multiple posture policies with a single service; how can I configure it ? I tryed with a Onguard configuration but I don't see any Roles (configurated on dot1x services:

     

    I need to apply a specific posture policies for corporates client and another one for Contractors.

    Thanks



  • 2.  RE: Posture Policy Enhancements

    EMPLOYEE
    Posted Apr 01, 2014 01:42 AM

    Are you using the agent or dissolvable?

     

    If its the agent then you can just use a simple trigger in your service so that posture would be picked. In my example I'm just using a MAC address but it could be a SSID/switch/ etc

     

    screenshot_02 Apr. 01 00.35.gif

     

    Then you chose which posture policy to trigger in the posture tab.

     

    screenshot_03 Apr. 01 00.40.gif



  • 3.  RE: Posture Policy Enhancements

    Posted Apr 02, 2014 09:38 AM

    Ciao,

    thank for replay. 

    However, my need will not let me this profiling. I'll explain:
    I am using a unique SSID for the corporate PC and consultants PC; I would like to use two different OnGuard's policies. For example:
    PC corporate: Check the presence of the antivirus corporate, the version....etc.
    PC consultants: Check any antivirus.

     

    I see that is possible starting CPPM 6.1 using Role. But I not undestand how.....

     



  • 4.  RE: Posture Policy Enhancements

    Posted Aug 12, 2014 03:31 AM

    When you create the Posture Policy, put an role in it.

     

    I actually see another issue: I wanted to check two Posture Policies, but as mentioned in the slide, the 'winning' policy is the one with BEST token. I tested and found once the Posture Policy wins, the Agent will only check against this Policy. Then other Posture Policies won't be checked any more.

     

    Regards,

    Patrick