Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass - Sending user mapping with domain prefix to Palo Alto

This thread has been viewed 27 times
  • 1.  ClearPass - Sending user mapping with domain prefix to Palo Alto

    Posted Oct 23, 2022 10:28 PM
    Hi everyone,

    I am setting up the Endpoint Context Server to send user-id and IP mapping to Palo Alto.
    The key requirement is to have the user name with the Netbios domain suffix.

    I have specified the username transformation with "Prefix NetBIOS name".
    However, PA is still receiving the <user-id> only,  in lieu of the desirable <domain>\<user-id>, like mydomain\user1

    Did I did not doing  it properly, or somewhere I have to specify the domain name ?
    I supposed  Clearpass will use the joined domain - domain name in the server manger/system without specify it.

    Thanks in advance for any suggestion.
    Many thanks



  • 2.  RE: ClearPass - Sending user mapping with domain prefix to Palo Alto
    Best Answer

    EMPLOYEE
    Posted Oct 24, 2022 06:14 AM
    One solution may be to change the Context Server Action used for your Palo Alto update. What is sent, is defined in those context server actions:
    You may change %{user} to some attribute that has the username in a format that you want to be sent (possibly the IETF:User-Name), or if all are in the same domain, you could change it to DOMAIN\${user}.

    The %{user} field has some smartness in it, which may be working against you now.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: ClearPass - Sending user mapping with domain prefix to Palo Alto

    Posted Oct 25, 2022 03:11 AM
    Thanks so much! That's brilliant!


  • 4.  RE: ClearPass - Sending user mapping with domain prefix to Palo Alto

    Posted 30 days ago

    Hi, can you share the output of the new conext server action?, please