Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Using CPPM API Access to bounce on-guard client

This thread has been viewed 0 times
  • 1.  Using CPPM API Access to bounce on-guard client

    Posted Nov 04, 2018 08:46 AM
    Hi guys,
    Is there a way to use api to bounce a client?
    So far i was able to successfully update endpoints with custom attributes with 3rd party variables.
    Now I'm trying to bounce a client as part of a workflow of infected endpoint.


  • 2.  RE: Using CPPM API Access to bounce on-guard client

    EMPLOYEE
    Posted Nov 04, 2018 09:11 AM
    No


  • 3.  RE: Using CPPM API Access to bounce on-guard client

    Posted Nov 04, 2018 09:31 AM
    Did you happen to know if it's in the roadmap?


  • 4.  RE: Using CPPM API Access to bounce on-guard client

    EMPLOYEE
    Posted Nov 05, 2018 07:12 AM

    You can bounce a client with CoA via the ClearPass API, just not a clientside bounce from the OnGuard agent.

     

    Is that agent bounce what you require, or will CoA work?



  • 5.  RE: Using CPPM API Access to bounce on-guard client

    Posted Nov 05, 2018 07:49 AM
    Well, i was looking for client bounce because i have a phone connected to
    the port and a pc behind it.
    CoA will bounce phone port not reflecting link flap onwards to the phone.
    If I'll send a CoA message of disconnect rather then port bounce will my pc
    going to renegotiate DHCP or will just reauthenticate?

    Anyway, could you please reffer me to the API method for making CoA?

    Thanks!


  • 6.  RE: Using CPPM API Access to bounce on-guard client
    Best Answer



  • 7.  RE: Using CPPM API Access to bounce on-guard client

    Posted Nov 08, 2018 01:08 PM

    Thanks A lot Herman.

    I Could succesfully query and disconnect the endpoint that was alerting for malware.

    When i"m done ill share my setup hope it could help others to build similar workflows.

     

    The only thing that wasn't working for me is using the $conatins operator with the filter parameter. Lucky for me i could walkaround it.