Security

 View Only
last person joined: 19 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Guest - Assign multiple operator profiles

This thread has been viewed 18 times
  • 1.  Clearpass Guest - Assign multiple operator profiles

    Posted Apr 07, 2022 11:09 AM
      |   view attached

    Hi all,

    On 1 of my Clearpass installations, I have operator profiles that can only see the vouchers in the Guest section - created by users having this specific operator profile. Now I have some users that need to see vouchers from multiple profiles, so I try to assign to those users all "admin priviliges" that apply to them based on AD Groups for each profile, however this does not seem to work and only 1 role is assigned when testing. In the Access Tracker I see that each role is assigned correctly, however, they may overwrite each other and so therefore it probably accepts 1 role from the 3?

    Does anyone have any idea how to assign multiple operator profiles to 1user in Clearpass Guest in order they can see all the vouchers from these profiles? I have 20 groups, and some will need to see from group 1-6-7 only, so I don't want to give full admin.. but just be able to assign all the operator profiles necessary through AD (which works for 1 group at a time)
    Thanks in advance!



    ------------------------------
    Cedric De Witte
    ------------------------------


  • 2.  RE: Clearpass Guest - Assign multiple operator profiles

    Posted Apr 08, 2022 10:32 AM
    Is your rule set to check all or any?

    ------------------------------
    David Broadbelt
    ------------------------------



  • 3.  RE: Clearpass Guest - Assign multiple operator profiles

    Posted Apr 08, 2022 11:43 AM
    Yes, all is selected. So 3 times the "admin priviliges" with each role is assigned.
    However, that does not work and only 1 is effectively used when logging in.
    Maybe this is not even possible, and I need to create 1 new operator profile to have access to these 3 roles? But this is less useful, as then the other 3 roles need also access to vouchers created by this new operator profile making it more complex.

    ------------------------------
    Cedric
    ------------------------------



  • 4.  RE: Clearpass Guest - Assign multiple operator profiles

    Posted Apr 08, 2022 11:44 AM
    Yes, all is selected. So 3 times the "admin priviliges" with each role is assigned.
    However, that does not work and only 1 is effectively used when logging in.
    Maybe this is not even possible, and I need to create 1 new operator profile to have access to these 3 roles? But this is less useful, as then the other 3 roles need also access to vouchers created by this new operator profile making it more complex.

    ------------------------------
    Cedric
    ------------------------------

    ------------------------------
    Cedric De Witte
    ------------------------------



  • 5.  RE: Clearpass Guest - Assign multiple operator profiles

    EMPLOYEE
    Posted May 04, 2022 10:07 AM
    As far as I know, you can only assign a single operator profile. This also is reflected in the Operator Logins - Translation Rules, where the mapping to the actual assigned role is done. In the below screenshot you can see that any Operator Profile Assignment has the 'Stop' flag so it is a first match.


    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------