Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Update attribute value of endpoints when CPPM Publisher is down

This thread has been viewed 1 times
  • 1.  Update attribute value of endpoints when CPPM Publisher is down

    Posted Dec 20, 2017 10:07 AM

    I set an enforcement profile to update attributes value of endpoints using ClearPass OnGuard. 

    For example, I made an attribute named "health status". And when OnGuard agent's status is healthy, the endpoint's "health status" is "Healthy".

     

     

    Today, my CPPM server had some problem and so I turned off the publisher. 

    Then, all services(RADIUS, TACACS, 802.1x, etc) worked well. But it couldn't update the "health status" of the endpoints. 

     

    Now, I wonder if the subscriber can't update any attribute of endpoints.  

     

    Thanks. 



  • 2.  RE: Update attribute value of endpoints when CPPM Publisher is down

    EMPLOYEE
    Posted Dec 20, 2017 10:13 AM
    Only the publisher has write access to the database. The publisher should never be down.


  • 3.  RE: Update attribute value of endpoints when CPPM Publisher is down

    Posted Dec 20, 2017 10:29 AM
    or you promote your subscriber as a publisher...


  • 4.  RE: Update attribute value of endpoints when CPPM Publisher is down

    Posted Dec 20, 2017 10:38 AM

    Thanks, Tim.

     

    But I made some services and role by these attributes.

    Is there any recommendation if my publisher has the problem like today?

     

    While I recover or troubleshoot my publisher, some services can't work unless the attributes are updated. 



  • 5.  RE: Update attribute value of endpoints when CPPM Publisher is down

    EMPLOYEE
    Posted Dec 20, 2017 10:47 AM
    What exactly was happening with your publisher? Do you have a TAC case open?


  • 6.  RE: Update attribute value of endpoints when CPPM Publisher is down

    Posted Dec 20, 2017 10:58 AM
    I did.
    My publsher didn't answer from any requests.
    And I found CPU load was nearly 100%.
    After rebooting, it worked well. But some services didn't work while rebooting.

    I'd like to prevent like this issue in future.


  • 7.  RE: Update attribute value of endpoints when CPPM Publisher is down

    EMPLOYEE
    Posted Dec 20, 2017 11:05 AM
    A publisher has to be up at all times to do database writes (post auth endpoint updates, Guest creation, device registration, Onboarding, etc)

    Authentication will continue if the publisher is down, but anything that requires a write, will not function.


  • 8.  RE: Update attribute value of endpoints when CPPM Publisher is down

    Posted Dec 20, 2017 11:08 AM
    Thanks. I got it.


    #AirheadsMobile


  • 9.  RE: Update attribute value of endpoints when CPPM Publisher is down

    Posted Dec 20, 2017 11:08 AM
    Thanks. I got it.


    #AirheadsMobile