Security

 View Only
last person joined: 7 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Policy Manager integrate with Checkpoint Firewall

This thread has been viewed 38 times
  • 1.  ClearPass Policy Manager integrate with Checkpoint Firewall

    Posted 19 days ago

    ClearPass Policy Manager issues when integrate with CheckPoint Firewall via Identity Awareness

    Step Configuration in ClearPass

    Create Endpoint Context Server and Target to Checkpoint gateway

    Created context server login/logout actions (just one of them is below). Provided them with shared-secret inside JSON content and link them to Check Point context server.

    Created HTTP based enforcement profile with necessary attributes:

    Linked this enforcement profile as action in our web auth policy:

    Then I tried to login user at OnGuard Agent and check log at Access Tracker, result:

    But NO identity awareness log sent to Checkpoint, I was check in Log collected from server but no send request from ClearPass

    Postauthctrl.log

    Am I missing some steps? How can I debug this part?

    Then i tried to replace Content tab like this 

    Then i tried to force send api at Access Tracker --> Server Actions but got Error: 500 Internal Error 

    How can ClearPass detect ip-address of User to send to Checkpoint ? Kindly help me to debug thanks! 



  • 2.  RE: ClearPass Policy Manager integrate with Checkpoint Firewall

    EMPLOYEE
    Posted 19 days ago

    Do you have accounting setup and working, including 'log interim accounting'?

    Do you see the Client IP address in Access Tracker under accounting?



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: ClearPass Policy Manager integrate with Checkpoint Firewall

    Posted 19 days ago

    Hi Herman, tk for your reply, for your questions: 

    Do you have accounting setup and working, including 'log interim accounting'? - Nope. We dont have AD Server so we only used LDAP Server for Authenticate user Login to OnGuard Agent. So now, as your questions, we must configure Accounting for CPPM system, right ? 




  • 4.  RE: ClearPass Policy Manager integrate with Checkpoint Firewall

    EMPLOYEE
    Posted 19 days ago

    I'm unsure if this integration works with just onguard, it normally is based on network authentication (802.1X or MAC-AUTH) and accounting information.

    As this is a quite uncommon deployment, you may check with Aruba TAC if they know if this may work.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: ClearPass Policy Manager integrate with Checkpoint Firewall

    Posted 15 days ago

    Hi, I was open case with TAC but they're always send old refer documents ... for now i just need to test how to send user's info to CheckPoint with only ip-address, username and role but no way for CPPM to search these infos ....

    Edited: Now we're partically about content to send to Checkpoint, but how to configure on ClearPass to auto trigger send API ? On Access Tracker i got result of RADIUS Response or Application Response but nothings send to Checkpoint




  • 6.  RE: ClearPass Policy Manager integrate with Checkpoint Firewall

    Posted 13 days ago

    update for my issue, Currently, we have resolved the issue for ClearPass to automatically send an API to Checkpoint. However, we are encountering an issue with the content that ClearPass sends. ClearPass is unable to retrieve the IP address value of the endpoint to include in the content, as shown in the Wireshark message below.

    So how can ClearPass send user information (ip address, username, etc.)? Or do I need to create a new library for the Endpoint so that the Context Server can reference it?



  • 7.  RE: ClearPass Policy Manager integrate with Checkpoint Firewall

    EMPLOYEE
    Posted 8 days ago

    ClearPass will need to know/learn the client IP address through (RADIUS) Accounting. Do you see in Access Tracker an Accounting tab? Does it show the client's IP address there?

    RADIUS Accounting needs to be enabled on your switch/ap/controller;

    In ClearPass make sure that 'Log Interim-Accounting' is enabled as well to process accounting updates and not only the start-stop.

    If you see %{ip} that means that there is no IP information for that client.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 8.  RE: ClearPass Policy Manager integrate with Checkpoint Firewall

    Posted 3 hours ago

    I have worked with Aruba TAC and there is no way for HTTP Based Enforcement to encapsulate User information during the Authentication process to send to CheckPoint. Therefore, I must revert to the option of using the Session Notification Enforcement profile with RADIUS Accounting. 

    So currently, I am confused about integrating with the Radius Server. How do I connect ClearPass and Checkpoint Firewall with Radius? How do I configure ClearPass? How can there be an accounting service when a User logs in to OnGuard? Please help me :)