Security

 View Only
last person joined: 6 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

PAN Clearpass Integration - Valid Variables?

This thread has been viewed 11 times
  • 1.  PAN Clearpass Integration - Valid Variables?

    Posted 12 days ago

    <uid-message><version>1.0</version><type>update</type><payload><login><entry name="%{user}" ip="%{ip}"/></login></payload></uid-message>

    Where is Clearpass pulling the values user and ip from? These are not formatted like most variables used in Enforcement Profiles.
    I would potentially like to send a certificate SAN instead of the CN to Palo Firewalls.

    Is there any documentation on this?
    I'm hoping that doing a post-auth Enforcement Update will get Clearpass to update the username in the Access Tracker and thus the POST, but if the API only pulls the original name from the auth then that work out.



  • 2.  RE: PAN Clearpass Integration - Valid Variables?

    EMPLOYEE
    Posted 11 days ago

    You are following the published document from https://arubanetworks.com/clearpassdocs?  The context server configuration allows for a username transformation and doesn't use the usual parameter notation.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------