Higher Education

 View Only
last person joined: 11 days ago 

Got questions on how to enable mobility in education? Submit them here!
Expand all | Collapse all

ClearPass Profile Conflict

This thread has been viewed 14 times
  • 1.  ClearPass Profile Conflict

    Posted Jul 21, 2017 11:05 AM

    Is there a way in clearpass to modify the device Catagory/OS Family/Name so ClearPass does not come up with a conflict again? Or worse yet ClearPass change the Device Catagory/OS Family/Name back to what it thinks the device is?

     

    I thought CleartPass was a database, what it the point of modifying a device if the system is going to change it back!



  • 2.  RE: ClearPass Profile Conflict

    EMPLOYEE
    Posted Jul 21, 2017 11:21 AM

    If the same finerprint is used again, it will use the same profile entry.

     

    The reason it changes is that a profile conflict is a very important part of a network policy to determine if a user has attempted to spoof a MAC address.

     



  • 3.  RE: ClearPass Profile Conflict

    Posted Jul 21, 2017 11:39 AM
    If I manually identify a device I do not want ClearPass changing the settings. I do not want CP telling me my Apply TV is an Aruba AP, nor do I want CP telling me an Apple watch is a smart iOS device.

    So in short your telling me that CP will override any device ID I set?

    Gary Naeger
    Network & Systems Engineer
    Planning, Research & Technology | Maryville University
    650 Maryville University Drive, St. Louis MO 63141
    (314) 529-9431
    Gander Hall, Room 4A
    gnaeger@maryville.edu

    [New Logo and Tagline eps]


  • 4.  RE: ClearPass Profile Conflict

    MVP
    Posted Jul 21, 2017 11:43 AM

    You are free to create any Endpoint attribute you need. I have some custom ones myself.

    ClearPass is free to update any Profiling attribute it internally uses too.

     

    tl;dr You need to create your own custom  attribute and perhaps open a TAC case on misidentifying fingerprints.



  • 5.  RE: ClearPass Profile Conflict

    Posted Jul 21, 2017 11:59 AM

    So i can apply a CP policy to a device based on an attribute? I will have to look into that a little more.

     

    We track campus ATV's in JAMF (casper). Using CP and the mobility controller I have a policy/acl that if the device is identified as an ATV it has internet access only. Users on the guest network or secure network can use the ATV for presentation.



  • 6.  RE: ClearPass Profile Conflict

    EMPLOYEE
    Posted Jul 21, 2017 12:00 PM

    AppleTV was just an example.



  • 7.  RE: ClearPass Profile Conflict

    MVP
    Posted Jul 21, 2017 12:01 PM

    That would not work for us since the majority of our Apple TVs, for instance are personally owned, usually by students.

    We do not want them in our JAMF.



  • 8.  RE: ClearPass Profile Conflict

    EMPLOYEE
    Posted Jul 21, 2017 12:09 PM

    Bruce - I've never come across an iOS device profiled incorrectly. Please open a TAC case if you're seeing that.



  • 9.  RE: ClearPass Profile Conflict

    EMPLOYEE
    Posted Jul 21, 2017 11:43 AM

    So if someone were to grab the AppleTV's MAC address and use it on their laptop to bypass network registration/security, you wouldn't want to know that?

    This is a core feature.

     

    If something is incorrectly being reprofiled, you should open a TAC case.



  • 10.  RE: ClearPass Profile Conflict

    MVP
    Posted Jul 21, 2017 11:46 AM

    I do not want Apple TVs identified as Aruba APs.

    I currently do not trust profiling information but it is not currently using DHCP information here.



  • 11.  RE: ClearPass Profile Conflict

    EMPLOYEE
    Posted Jul 21, 2017 11:48 AM

    Then a TAC case should be opened. That is not correct.

     

    There's a difference between conflict detection and incorrect profiling.



  • 12.  RE: ClearPass Profile Conflict

    Posted Jul 21, 2017 11:52 AM

    Ease of access it more important. I have firewalled my datacenter. If they look like an ATV the only place they can go is the Internet. Then any "Guest" or anyone on the secure wlan can access their device using airplay.