Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

clearpass dhcp packet processing

This thread has been viewed 3 times
  • 1.  clearpass dhcp packet processing

    Posted Apr 19, 2018 06:18 AM

    Might be a silly quesstion..

     

    I've configured our router endpoints to forward dhcp requests not not only to our UoY dhcp server but also the master publisher for each of our two clearpass clusters.

     

    quesiton, do I have to point dhcp requsts at the aster publisher or can I point them at a secondary node as well ? Just thinking of how a cluster might provess inbound dhcp requests if the publisher os offline for some reason

     

    A



  • 2.  RE: clearpass dhcp packet processing

    EMPLOYEE
    Posted Apr 19, 2018 06:40 AM

    You have to configure it to send dhcp packets to both nodes. You have more details of ClearPass behaviour in "ClearPass Profiling Technote".



  • 3.  RE: clearpass dhcp packet processing

    Posted Apr 19, 2018 07:00 AM
      |   view attached

    o.k. onlyversion of that I can find is cppm 6.5 and yes can remeber an endpoint classification checkboc being there at one point but in 6.7 its not there, All I see is as shown in the png file



  • 4.  RE: clearpass dhcp packet processing

    Posted Apr 19, 2018 11:08 AM

    That would imply that for our production cluster I'd have to send it to 6 servers

     

    Can anyone point me to a clearpass profiling technique doc for 6.7.2?

    Can't see any refernece to a checkbox for "allow this node to perform endpoint classification"



  • 5.  RE: clearpass dhcp packet processing
    Best Answer

    EMPLOYEE
    Posted Apr 19, 2018 11:45 AM

    You can check the Release Note of CPPM 6.7:

    Screen Shot 2018-04-19 at 17.43.47.png



  • 6.  RE: clearpass dhcp packet processing

    Posted Apr 19, 2018 12:17 PM

    So just to check

     

    If we don't specifiy a primary and secondary master server in zone, the server with the highest UUID gets selected.

     

    If we're pointing dhcp requests at our master publisher but the primary server is one of our secondaries because we haven't set the master server in a zone then does that mean that our dhcp collecctor won't work?

     

    Have tried this on our dev cluster and "stuff happened"  unfortunately a colleague was also doing things at the same time to the device we were using to test this so this is just a check

     



  • 7.  RE: clearpass dhcp packet processing

    Posted Apr 19, 2018 12:22 PM

    Just tracked this down as well but many many  thanks for the info

    Rgds

    Alex