Security

 View Only
  • 1.  ClearPass Onguard

    Posted Apr 01, 2026 03:54 PM
    I'm having a problem with ClearPass: some people with Windows laptops, after restarting, or for example, changing their password during the day, then locking Windows and logging back in, OnGuard doesn't perform a health check, and the wireless connection remains connected but without internet.
    
    The connection only returns to normal if they turn off Wi-Fi and turn it back on, then it goes through the posture process and connects normally.
    
    My opinion is that perhaps ClearPass stores some cache and doesn't validate again just by restarting or unlocking the laptop.
    
    I would like to know if anyone has seen a similar problem, and if it would be possible to force OnGuard posture every time the laptop is unlocked or restarted.
    
    I'm on version 6.11.12 Active-Passive Cluster.


    -------------------------------------------


  • 2.  RE: ClearPass Onguard

    Posted Apr 02, 2026 05:16 AM

    Yes, ClearPass keeps a cache of posture data, as well the agent should be configured to redo/repost status regularly, at least before the posture status expires.

    It may be best to go through the configuration with your HPE Networking partner, as there is no generic issue that I'm aware of, so it must be something specific in your setup.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: ClearPass Onguard

    Posted Apr 06, 2026 03:14 PM

    Why are you using MS-CHAPv2 in 2026? Also consider integrating ClearPass with your MDM instead of using OnGuard.

    -------------------------------------------



  • 4.  RE: ClearPass Onguard

    Posted Apr 07, 2026 08:12 AM
    Hello Ahollifield,
    
    Could you provide me with some information or documentation so I can better understand this option? Thank you.
    -------------------------------------------



  • 5.  RE: ClearPass Onguard

    Posted Apr 07, 2026 08:18 AM
    Which option? Using certificate based authentication? Or MDM? Both?

    Do you have a PKI? What MDM platform do you use to manage your devices?





  • 6.  RE: ClearPass Onguard

    Posted Apr 07, 2026 09:30 AM

    MDM, we use Intune

    -------------------------------------------



  • 7.  RE: ClearPass Onguard

    Posted Apr 07, 2026 09:37 AM
    You should integrate InTune with ClearPass instead of using OnGuard. ClearPass can pull endpoint compliance data from InTune.