Security

 View Only
  • 1.  ClearPass OnGuard - Posture Policy - Parameter checks

    Posted Aug 26, 2025 01:20 PM

    Hello All

    We are planning to add more posture checks in our existing ClearPass Universal SHV plugin for Windows 10 & Windows 11 desktops.

    Few checks that are in consideration to be added:

    1. NTP/DNS: Clock drift < 2 min
    2. Local admin disabled, no extra admin accounts
    3. UEFI secure boot enabled; TPM 2.0 owned

    Need guidance on how could we configure this in OnGuard Posture plugin from the list of available health checks

    Thank you..!



    -------------------------------------------


  • 2.  RE: ClearPass OnGuard - Posture Policy - Parameter checks

    Posted Aug 26, 2025 02:23 PM

    Those are more administrative requirements/settings than something that the posture validation would be looking at.  What purpose is there for checking on these items in posture evaluation prove?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: ClearPass OnGuard - Posture Policy - Parameter checks

    Posted Aug 29, 2025 01:31 AM

    Thank you for your response @chulcher

    If looking from security value for a bank environment

    • misconfigured DNS can redirect traffic to phishing/malware sites
    • NTP is critical for event correlation
    • Secure Boot/TPM check to ensure endpoints are installed with golden image

    For this we are trying to add new checks along with exiting checks (AV, Windows Hotfixes)

    -------------------------------------------



  • 4.  RE: ClearPass OnGuard - Posture Policy - Parameter checks

    Posted Aug 29, 2025 12:22 PM

    DNS - don't allow DNS queries to any servers other than the ones you want to be used; use a custom script to validate.

    NTP - check to see that the service is running, use a registry check or custom script to validate NTP configuration.

    "golden image" - use a registry check or custom script to validate unique identifiers of the Windows installation.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: ClearPass OnGuard - Posture Policy - Parameter checks

    Posted Sep 02, 2025 05:53 AM

    You could have a look at Custom scripts for Onguard, which allow you to run basically any check you can think of as long as you know how to check in a script.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 6.  RE: ClearPass OnGuard - Posture Policy - Parameter checks

    Posted Sep 02, 2025 07:01 AM

    @Herman Robers

    Thank you for your insight. One doubt, I would like to ask if adding more checks will degrade ClearPass Performance for an environment like financial institution.

    -------------------------------------------



  • 7.  RE: ClearPass OnGuard - Posture Policy - Parameter checks

    Posted Sep 02, 2025 09:24 AM

    The OnGuard posture assessment occurs on the client device, then the result is sent to ClearPass for policy enforcement.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------