Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Radius Attribute from CPPM is not observed on IAP, but it seems to be sent

This thread has been viewed 1 times
  • 1.  Radius Attribute from CPPM is not observed on IAP, but it seems to be sent

    Posted May 22, 2018 10:48 PM

    Hello. I'd like to ask for a guidance one more time.

     

    My goal is to start working with Clearpass, and i'm trying to bring simple lab. I have Win2016server, with AD working fine, CPPM 6.7, IAP305 latest, win7 as wifi client.

     

    The task is - on the CPPM catch up users, who are member of Grupe1, attach them a role, by that role "enforce" them to be assigned a role on IAP with simple deny icmp any any (further - denyping).

    The problem is that i don't even see CPPM passing the attribute Aruba-User-Role to IAP on the packet capture and the IAP is not catching it up also.

    Here is the setup:

    192.168.200.222 - CPPM, 192.168.100.20 - IAP

     clearpass01.png

     

     As you can see policy is UserIsGrupe1

     

    Policy:clearpass02.png

     Nevermind the condition, pl_test (my role) is the default role - and it is working. (see below)

     

    Here is the enforcement profile:clearpass04.png

    ... and the Attribute i'd like IAP to receive.

       

    The Enforcemenet policy

    clearpass07.png

     

     Again, the condition might not work (thus it probably works) - but the Default Profile should work anyway.

     

     

     

    And what i see on the packet capture:clearpass05.pngAs you can see Accept-Accept, but there is no Aruba's vendor attribute. And IAP also don't see it.

     

    Here is output from tracker:clearpass11.png

     

    And here is the Ouput:

    clearpass12.png

     

    Please, note - the Attribute is present, but it is not noticed on the packet capture, neither IAP recognizes it.

     

    Here is just in case config from IAP:

    clearpass13.png

    All users fallback into ArubaRadio1 instead of denyping.

     

    I understand that there is stupid-little-something that i'm missing for a such trivial case, but i can't catch it.

    I'd really appretiate any advice. Thank you!

     

     

     

     

     

     

     

     

     

     

     

     



  • 2.  RE: Radius Attribute from CPPM is not observed on IAP, but it seems to be sent

    EMPLOYEE
    Posted May 22, 2018 10:51 PM
    Do you have the role defined on the IAP?


  • 3.  RE: Radius Attribute from CPPM is not observed on IAP, but it seems to be sent

    Posted May 22, 2018 10:57 PM

    I think i'm.

    clearpass14.png

     

     

    Please also find attached CPPM log and packet capture files (just in case..)

     

    Thank you!

    Attachment(s)

    txt
    clearpass-pcap.log.txt   8 KB 1 version
    txt
    clearpass.log.txt   15 KB 1 version


  • 4.  RE: Radius Attribute from CPPM is not observed on IAP, but it seems to be sent

    EMPLOYEE
    Posted May 22, 2018 10:56 PM

    1. In your enforcement profile, remove the device group requirement.

    2.The "Aruba-User-Role" VSA does not require a role assignment rule on the IAP. The IAP sees that attribute and changes the user role

    3.  I don't see "denyping" as a defined role on the IAP.  If the role you return with the VSA does not exist, the user just gets the default role.



  • 5.  RE: Radius Attribute from CPPM is not observed on IAP, but it seems to be sent

    Posted May 22, 2018 11:01 PM

    Thank you cjoseph. But no luck - nothing has changed (after device removal)

    And regarding the role assignment on IAP - i've tried both ways, just the pointing manually with access rule seemed as a required prerequisite. But it should work anyway i think. And it isn't.

     

     

     



  • 6.  RE: Radius Attribute from CPPM is not observed on IAP, but it seems to be sent
    Best Answer

    EMPLOYEE
    Posted May 24, 2018 08:30 AM

    Try to disable Monitor Mode in your service. The screenshot shows it is enabled.

     

    Monitor Mode will return just an Access Accept, regardless policy/authentication, and is intended to see what would happen without actually doing it. From your description, this matches what you see.



  • 7.  RE: Radius Attribute from CPPM is not observed on IAP, but it seems to be sent

    Posted May 24, 2018 08:55 AM

    That is exactly what is was.

    Thank you very much! I can continue now :)