Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

smart device profiling

This thread has been viewed 11 times
  • 1.  smart device profiling

    Posted Nov 06, 2014 12:56 PM

    hi,

    we have clearpass with aruba controller with dot1x authentication,

     

    i want to profile my smart device , but it doesnt work, how can i do it? i have create role name is smart device, and role mapping if autho endpoint repo is equla to smart device give him smart device role

     

    then of enforcment policy i said id endpoint is not equal profile => send dhcp only profile whic is inly send role on controller with any any service dhcp permit , and aruba termination profile, 

     

    i have enabled check boxes to nable profiling 

     

    please waiting your help

     

    thanks

     



  • 2.  RE: smart device profiling

    Posted Nov 06, 2014 01:13 PM
    You add your ClearPass as an DHCP relay on your Client VLAN at the Core or Distribution switch where the VLAN leaves


  • 3.  RE: smart device profiling

    Posted Nov 06, 2014 01:15 PM

    i have added cppm and dhcp ip address as ip helper on each vlan interface on my controller,

    should i add them also on same vlan on swicthes also?



  • 4.  RE: smart device profiling

    EMPLOYEE
    Posted Nov 06, 2014 01:17 PM
    Yes it needs to be upstream on the client's gateway interface.


  • 5.  RE: smart device profiling

    Posted Nov 06, 2014 01:29 PM

    As cappalli mentioned it is more efficient to do at the Core or Distribution switch where the SVI actually lives

     

    To use the information receive by the ClearPass you need to do the following 

     

    - First Add the endpoint database as Authorization Source to your service

    .

    - Then add the Category/OS Family as Roles/Attributes

    2014-11-06 12_17_03-ClearPass Policy Manager - Aruba Networks.png

     

    - And then you can use those in your enforcement policy to apply a certain enforcement profile

    2014-11-06 13_23_41-ClearPass Policy Manager - Aruba Networks.png

     



  • 6.  RE: smart device profiling

    Posted Dec 01, 2014 07:10 AM

    hi, i have tried the same configuration, but each time am getting an error getting catagory and os type from endpoint ,

     

    do i have to create a specific role on initial role on controller?

     



  • 7.  RE: smart device profiling

    EMPLOYEE
    Posted Dec 01, 2014 07:13 AM

    You can use the logon role as a profile role. As the first rule in your service, you can do Category NOT_EXISTS, return the logon role. Be sure the profiler is enabled in your service.



  • 8.  RE: smart device profiling

    Posted Dec 01, 2014 09:14 AM

    do, i need to bounce the client again?

    do i have to add another enforcment profile to update or bounce client?

     

    thanks