Security

 View Only
  • 1.  Clearpass ENforcement policy rules question

    Posted Dec 08, 2024 08:38 PM

    Hi

    I have this conditions in our clearpass and I'm trying to understand what it does.. (both conditions basically contain the same rules editor.. (ro vs rw is the diff)



  • 2.  RE: Clearpass ENforcement policy rules question

    Posted Dec 09, 2024 07:33 AM

    This would return the CISCO-SW-RW_EPRO enforcement profile if the AD_CISCO-RW_ROLE is present in the authentication.

    If that is not the case, it would return the CISCO-SW-RO_EPRO enforcement profile if the AD_CISCO-RO_ROLE is present in the authentication.

    If that's also not the case, the default enforcement will be returned (which is not displayed in your screenshot).

    This is basic ClearPass knowledge, which is part of any ClearPass training.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Clearpass ENforcement policy rules question

    Posted Dec 09, 2024 11:03 AM

    Thank you. I never had any training so apologies. Anyway, how do I add command authorization to this? (i.e. if it returns AD_Cisco-RW_Role , check which ad group they are in?  assign priv 15 for  network engineers or assign priv 7 if network analysts.. thanks




  • 4.  RE: Clearpass ENforcement policy rules question

    Posted Dec 10, 2024 10:33 AM

    Based on what is shown, you'd modify the role assignment criteria to look at the necessary authorization items (group membership) and set the role appropriately.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------