Security

 View Only
last person joined: 7 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Endpoint IP Address View

This thread has been viewed 33 times
  • 1.  ClearPass Endpoint IP Address View

    Posted Nov 06, 2022 06:09 AM
    Is there a reason the IP address is not listed in either the Endpoint Profiler or Endpoints Configuration views?  I understand that they can change quickly, so may not always be up-to-date, but most of my IPs change infrequently, and I'm looking for a view that I can breakdown by device type/IP.

    Thanks!
    Scott


  • 2.  RE: ClearPass Endpoint IP Address View

    MVP EXPERT
    Posted Nov 06, 2022 03:04 PM
    Hi Scott,

    Do you have an DHCP IP helper address on your switch (per client vlan) that's pointed to your ClearPass server? When ClearPass received the DHCP requests of the clients it will not answer the client but use the DHCP information to profile your clients in the endpoint database automatically.

    ------------------------------
    Marcel Koedijk | MVP Expert 2022 | ACEP | ACMP | ACCP | ACDP | Ekahau ECSE | Not an HPE Employee | Opinions are my own
    ------------------------------



  • 3.  RE: ClearPass Endpoint IP Address View

    Posted Nov 07, 2022 11:01 AM
    Sorry - I should have been more clear.  I can click through individual endpoints and the IP info is present (from IP helper data).

    My question was related to the "Monitoring> Profiler and Network Scan> Endpoint Profiler" and "Configuration> Identity> Endpoints" views.  In these views, I see info. like MAC Address, Hostname, Device Category, Device OS Family, Status.  I was wondering if there is a place to see all of this data along with the current IP address(es) in a single view.

    Thanks!


  • 4.  RE: ClearPass Endpoint IP Address View

    MVP EXPERT
    Posted Nov 07, 2022 02:55 PM
    Hi Scott,

    Could you explain where you need it for, what purpose? In the Endpoint Profiler you don't see the IP addresses. But in the endpoint database you have all attributes together but is visible per endpoint entry (Device Category, Family, Devicename, Hostname, IP).

    Maybe the Insight database is something where your looking for (have to enable it under Administration > Server Configuration > Server).


    ------------------------------
    Marcel Koedijk | MVP Expert 2022 | ACEP | ACMP | ACCP | ACDP | Ekahau ECSE | Not an HPE Employee | Opinions are my own
    ------------------------------



  • 5.  RE: ClearPass Endpoint IP Address View

    Posted Nov 07, 2022 03:26 PM
    It would be useful to filter on.  For instance, say I expect a certain IP range to be used for all of my Security cameras...I could filter on 10.x.x.x and see all endpoints that have been profiled, and what type of device they're being identified as. 

    Insights would work for me, but that's assuming everything has passed through a dot1x process - I'm still in the phase where I'm enumerating all of my endpoints.


  • 6.  RE: ClearPass Endpoint IP Address View

    EMPLOYEE
    Posted Nov 10, 2022 09:48 AM
    You can filter in the Endpoint repository on the client IP:
    Would that work?

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 7.  RE: ClearPass Endpoint IP Address View

    Posted Nov 10, 2022 10:21 AM
    Yeah, that definitely works.  Visually, I would think it could make sense to include the IP as an optional column in the main view, though.

    Thanks for the responses.