Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

How can I integrate CPPM with Palo Alto firewall version 4.x?

This thread has been viewed 0 times
  • 1.  How can I integrate CPPM with Palo Alto firewall version 4.x?

    Posted Mar 24, 2014 05:33 PM

    Customer has implemented ClearPass and Palo Alto, but is still running 4.1 of Palo Alto code.  They would like to use the PA user-id agent to communicate with ClearPass.  Apparently this was available with Amigopod, but not clear how to integrate with ClearPass Guest. 

     

    Any help would be greatly appreciated. 

     



  • 2.  RE: How can I integrate CPPM with Palo Alto firewall version 4.x?

    EMPLOYEE
    Posted Mar 24, 2014 05:50 PM


  • 3.  RE: How can I integrate CPPM with Palo Alto firewall version 4.x?

    Posted Mar 25, 2014 08:50 AM

    Colin,

     

    I have that document, but it is specific to Palo Alto version 5.X or 6.X.  Customer is running v4.1 of Palo Alto and the document states that if you want to integrate CP with PA prior to v5 to contact your Aruba Clearpass specialist.  Prior to CP, Amigopod could make use of the PA user-id agent, but I haven't found anything indicating how this would be configured with CP.

     

    Any ideas?

     



  • 4.  RE: How can I integrate CPPM with Palo Alto firewall version 4.x?

    EMPLOYEE
    Posted Mar 25, 2014 12:29 PM

    jsayer2221,

     

    The person who wrote the document said that the PanOS 4.x was not available for testing.  I don't think we have further information on integrating that version of PanOS.



  • 5.  RE: How can I integrate CPPM with Palo Alto firewall version 4.x?

    Posted Mar 25, 2014 02:42 PM

    ok.  found a video that showed PA user-id working with Amigopod but was a couple of years old with old code versions on all devices.  Also had very little detail as to what was configured on either the Amigopod or Palo Alto side unfortunately. 

     

    checking to see when/if customer is planning to move to PA 5.x code.