Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

clearpass internet access

This thread has been viewed 31 times
  • 1.  clearpass internet access

    Posted May 18, 2022 09:26 AM
    cppm need to online update fingerprint,the customer wants to restrict CPPM's access to the Internet, which URLs and ports need to be allowed on the firewall?

    ------------------------------
    tan xiaofeng
    ------------------------------


  • 2.  RE: clearpass internet access

    Posted May 19, 2022 03:21 AM
    clearpass.arubanetworks.com - 443
    https://www.arubanetworks.com/techdocs/ClearPass/6.10/PolicyManager/Content/CPPM_UserGuide/Admin/Software_Updates.htm?Highlight=clearpass.arubanetworks.com

    We've did find allowing access to 443 on the IP address worked better than the domain name - https://104.36.248.89/ did the job.


  • 3.  RE: clearpass internet access

    EMPLOYEE
    Posted May 20, 2022 10:23 AM
    I would strongly recommend using the domain name, as the IP may change every now and then. Or create a rule that allows both IP and domain.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 4.  RE: clearpass internet access

    Posted May 21, 2022 02:56 AM
    Thanks guys!


    Another question,starting from 6.10, Software updates are authenticated using a token rather than username and password. Tokens are obtained by clicking the Generate Token button in the HPE PassPort Credentials,Which URLs and ports need to be allowed on the firewall so that tokens can be generated and updated

    ------------------------------
    tan xiaofeng
    ------------------------------



  • 5.  RE: clearpass internet access

    EMPLOYEE
    Posted Jun 09, 2022 05:05 AM
    The update token is generated from the admin's browser, then transferred into the ClearPass configuraion. No special/additional access needed from the ClearPass appliance itself.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------