Security

last person joined: 21 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all
This thread has been viewed 1 times
  • 1.  User Rules

    Posted Aug 28, 2014 09:19 AM

    I'm trying to apply a user rule to our primary SSID to put Windows XP devices into a limited role. I was testing with moving a specific mac address into a new role and I can see the number of hits incrementing but the set role is never applied.

     

    Authentication User Rules.png

     

    Here is where I am applying it to the AAA profile:

    Authentication Profiles.png

     

    It seems that I'm missing something and I was hoping for a nudge in the right direction.

     

    Thanks,


    Rosie



  • 2.  RE: User Rules

    Posted Aug 28, 2014 09:23 AM

    what role did it get applied ?

     

     



  • 3.  RE: User Rules

    Posted Aug 28, 2014 09:25 AM

    The role it gets is from the radius server rules passed by NPS.



  • 4.  RE: User Rules
    Best Answer

    EMPLOYEE
    Posted Aug 28, 2014 09:28 AM
    You cannot override a rule sent as a VSA


  • 5.  RE: User Rules

    Posted Aug 28, 2014 09:30 AM

    Do you know if I can create an NPS rule to set role based on a dhcp fingerprint? I account for all login cases via the VSA so it sounds like user deravations wouldn't work at all then.

     

    Thanks,

     

    Eric



  • 6.  RE: User Rules

    EMPLOYEE
    Posted Aug 28, 2014 09:32 AM

    I don't believe NPS can profile a device or use DHCP fingerprints.

     

    Does this SSID serve only corp assets or BYOD as well? 

     

    If they're all domain joined, you can script the creation of a group with all the xp machines in it and use that group in your policy. 



  • 7.  RE: User Rules

    Posted Aug 28, 2014 09:38 AM

     

    @cappalli wrote:

    I don't believe NPS can profile a device or use DHCP fingerprints.

     

    Does this SSID serve only corp assets or BYOD as well? 

     

    If they're all domain joined, you can script the creation of a group with all the xp machines in it and use that group in your policy. 


    The SSID serves all users and none of the machines should be joined to the domain anymore. Most of them are BYOD.



  • 8.  RE: User Rules

    EMPLOYEE
    Posted Aug 28, 2014 09:33 AM

    take a look here:

     Role-Derivation.jpg



  • 9.  RE: User Rules

    Posted Aug 28, 2014 09:39 AM

    @SethFiermonti wrote:

    take a look here:

     Role-Derivation.jpg


    Thanks for the visual!