My Clearpass integrator wants to use DHCP options to profile traffic. This may seem straight forward but I'm not able to use DHCP relay to provide this traffic to CPPM so I think my only option is to setup a port mirror and for CPPM to use the SPAN port.
Architecture:
- Fortigate 2500e HA providing all Layer 3 and operating as the DHCP server. Fortigate firewalls cannot be both a DHCP server & DHCP relay. The specific model of firewall also does not support SPAN.
- 2930M switch stacks Layer 2 only. 8 VLANs.
- ClearPass C1000 running 6.8.5.120250. Publisher & Subscriber
- LACP LAG between the switches and the Fortigate firewalls.
Mirror Port Configuration:
- I only need to send the DHCP requests from the client to CPPM so I'm planning on mirroring inbound traffic for each of the LACP members to the mirror port.
Questions:
1. For all 8 vlans, if the physical port is mirrored, is there a way for CPPM to see the traffic for all 8 vlans?
- Procurve mirroring documentation states that only the traffic for the vlan that the mirror port is in will be shown. So can the mirror port be a trunk port?
2. Any other suggestions on how to get the requested information to CPPM for profiling? VLAN mirroring, SNMP-Traps, etc?
Thanks in advance.