Security

 View Only
last person joined: 6 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM profiling without Dhcp option

This thread has been viewed 20 times
  • 1.  CPPM profiling without Dhcp option

    Posted 9 days ago

    hi all,

    I am concerned about Clear Pass's profiling, how can I profile devices without an IP helper as those endpoints will have static IPs not dynamic ?



  • 2.  RE: CPPM profiling without Dhcp option

    EMPLOYEE
    Posted 8 days ago

    I hope this helps:  https://www.arubanetworks.com/techdocs/ClearPass/6.12/PolicyManager/Content/CPPM_UserGuide/PolicyProfile/Collectors.htm



    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    HPE Design and Deploy Guides: https://community.arubanetworks.com/support/migrated-knowledge-base?attachments=&communitykey=dcc83c62-1a3a-4dd8-94dc-92968ea6fff1&pageindex=0&pagesize=12&search=&sort=most_recent&viewtype=card
    ------------------------------



  • 3.  RE: CPPM profiling without Dhcp option

    Posted 8 days ago

    thank you i tried the snmp way but still not getting all the info I need like device category and os, etc... I even changed the SNMP options in the server configuration and made the poll trigger for 10 minutes but still the endpoints don't update.

    the accounting is working well between switch and cppm but the only issue I have now that profiling static devices.




  • 4.  RE: CPPM profiling without Dhcp option

    Posted 7 days ago

    I am still learning myself, but in my experience. 90% of valuable profiling information comes from DHCP with the helpers. I doing SNMP "Network Scans" in tandem with NMAP "Subnet Scans" with the SNMP scans able to read the ARP table may tie the Static Addresses to the clients for even better profiling. But being able to Fill out the Device Fingerprints effectively is Best with the DHCP Helpers. There may be significant Fingerprint Rule generation required for your use case of static IP devices. 

    All of this is said with the hopeful correction by someone smarter than me. But Static IP devices have always been a bane for me. 




  • 5.  RE: CPPM profiling without Dhcp option

    Posted 6 days ago

    Yup, very true.  DHCP is a wealth of knowledge.  SPAN-based profiling tools are your friend here for static IP devices.




  • 6.  RE: CPPM profiling without Dhcp option

    Posted 7 days ago

    What is the NAD?  Cisco Device Sensor, SNMP, NMAP.

    SPAN based profiling utilities such as Aruba Central Device analytics, Ordr, Medigate, Armis, etc.