Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

separate services on devices

This thread has been viewed 0 times
  • 1.  separate services on devices

    Posted Aug 06, 2013 03:48 AM

    I have a cluster of devices across the world and I would like to have separate services running on the subscriber devices. Is this possible? it looks like the services are pushed out from the publisher and cannot be disabled/enabled on the subscriber.The issue here is that SSIDs etc will be the same in each region so devices in the US will match the same service as devices in the UK - however I would like them to authenticate to local sources. If I configure a service to point to the UK AD, devices in the US will authenticate against this source - traversing the WAN instead of locally. Will I need to find a way to match a service depending on where the NAD is located.



  • 2.  RE: separate services on devices

    EMPLOYEE
    Posted Aug 06, 2013 04:15 AM
      |   view attached
    In your services you could add a filter on the NAD ID and/or IP, ap name, etc along with the ssid.



  • 3.  RE: separate services on devices

    Posted Aug 06, 2013 05:07 AM

    It would be a good solution if I could group all the UK NAD devices under Network>Device groups and then match the service on the group - can this be done i've looked under the service rule type/name but cant find a match.



  • 4.  RE: separate services on devices

    EMPLOYEE
    Posted Aug 06, 2013 08:12 AM

    That sounds like a good idea! You should create a feature request.

     

    https://arubanetworkskb.secure.force.com/cp/ideas/ideaList.apexp



  • 5.  RE: separate services on devices
    Best Answer

    Posted Aug 06, 2013 08:35 AM

    Yes, you can do this; I"ve used it many times.  The filter is:

     

    Connection --> NAD-IP-Address --> BELONGS_TO_GROUP --> Name of your group 

     

    cp-nad-group.jpg

     

    This coupled with services for each region will allow UK controllers to authenticate against UK domain controllers and so on.



  • 6.  RE: separate services on devices

    Posted Aug 06, 2013 12:01 PM

    That seems to be exactly what I need - thanks for the solution.