Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

airwave initial config

This thread has been viewed 1 times
  • 1.  airwave initial config

    Posted Nov 12, 2013 06:01 AM

    Hi guys,

     

    I set up airwave for trial and I have some doughts..

     

    Initially i told Airwave to manage my controller and all my Aruba controller config was gone.. Not a god start..

    What is desired configuration for Airwave ? Desired for him , not for me.. ;)

     


    God bless i had several backups of controller config..

     

    Then i put airwave in monitor mode and its working more or less.

     

    My needs:


    1. is it possible to test a cisco device being monitor with airwave? without clearing configuration? monitor mode?

    2. I don´t have firewall data on Airwave

     

     

    regards



  • 2.  RE: airwave initial config

    EMPLOYEE
    Posted Nov 12, 2013 07:12 AM

    DO NOT ADD A NEW DEVICE IN MANAGE MODE!!!  EVER!  

     

    Add a new device in monitor only...and if you wish to manage the config (to make changes via Airwave), then ensure that it is imported and marked as GOOD.  Once it is marked GOOD within Airwave, you can toggle the mode to Manage and it will not overwrite the config with someting undesired from Airwave.  

     

    The issue you ran into was that Airwave had an initial config for that particular device type.  When you added it in manage mode, Airwave overwrote the config with what it thought were its settings.  



  • 3.  RE: airwave initial config

    EMPLOYEE
    Posted Nov 12, 2013 07:14 AM
    Each folder and group has a config option for Monitor only and
    Monitor+Firmware updates.

    Once you've added the device into a monitor group, you can import the
    devices config to AirWave and then potentially change the group to managed
    mode to make any further changes.


  • 4.  RE: airwave initial config

    Posted Nov 12, 2013 07:47 AM

    Now I know NEVER use MANAGER MODe in first place;)

     

    where do I import the aruba config to airwave for further manage the controller via airwave?

     

    ANother thing : How can i Add Clearpass policy manager to monitor? I am not able to find in clearpass SNMP settings

     

    regards



  • 5.  RE: airwave initial config

    EMPLOYEE
    Posted Nov 12, 2013 07:52 AM
    You can import in the audit tab for that device.

    Clearpass snmp settings are found in the administration menu.

    Sent from my iPhone


  • 6.  RE: airwave initial config

    EMPLOYEE
    Posted Nov 12, 2013 08:12 AM

    cp-snmp.png



  • 7.  RE: airwave initial config

    Posted Nov 12, 2013 08:56 AM

    Hi Guys ,

     

    Thanks for the help..

     

    I was able to configure SNMP on clearpass, but i could only catch CPPM on airwave by http credentials:)

     

    Another last thing for now... Firewall is enable ( AMP setup - general page under the Additional AMP Services section.) but I can´t see any data in airwave.

    why?

     

    Regards



  • 8.  RE: airwave initial config

    EMPLOYEE
    Posted Nov 12, 2013 08:58 AM
    You MUST have firewall visibility enabled on the controllers and also have AMON enabled to send the data to Airwave

    Here is the command for AMON.

    mgmt-server type amp primary-server 192.168.1.18


  • 9.  RE: airwave initial config

    Posted Nov 12, 2013 12:25 PM

    funtastic..working only enabling mgmt server on aruba controller.

     

    We have several Cisco switches ( more than 50) .

     

    The don´t have snmp enable.. is it possible to catch them with any other protocol? LIke telnet credencials?

     

    Regards



  • 10.  RE: airwave initial config

    EMPLOYEE
    Posted Nov 12, 2013 12:27 PM

    The telnet/ssh/enable credentials are used for running commands and updating configs. To do monitoring, you would need to enable SNMP.



  • 11.  RE: airwave initial config

    Posted Dec 19, 2013 06:24 AM

    Hi All

     

    I am trying to set airwave to see all my nortel switches but I can´t seem to be able to go ahead.

     

    I have all snmp set to public in the switches and when I do a scan none of the switches shoes up.

     

    Any help?

     

    Regards