Security

 View Only
Expand all | Collapse all

Clearpass profiling issue

This thread has been viewed 83 times
  • 1.  Clearpass profiling issue

    Posted Dec 02, 2020 04:38 AM
    Hi,

    Has someone got the profilig part of Clearpass working on another vendor switch?
    I'm using Ruckus ICX switching, but can't get the profiling to work.

    Kind regards,

    ------------------------------
    Thomas Willems
    ------------------------------


  • 2.  RE: Clearpass profiling issue

    Posted Dec 02, 2020 07:42 AM
    Hi,

    Did you add ClearPass IP as DHCP helper in your environment?

    ------------------------------
    Ayman Mukaddam
    ------------------------------



  • 3.  RE: Clearpass profiling issue

    Posted Dec 02, 2020 07:53 AM
    Hi,

    Yes it is.
    What I could see is that my manual COA action does work, but not the automatic one of the service.

    Kind regards,

    ------------------------------
    Thomas Willems
    ------------------------------



  • 4.  RE: Clearpass profiling issue

    Posted Dec 02, 2020 01:40 PM
    So you've completely pivoted from profiling to a Dynamix-AuthZ question, please be clear about the assistance you want from the community please.

    Can you confirm if the switch is correctly forwarding DHCP messages {DIscover/Offer} to CPPM, it will use specifically DHCP Options 55 {from client} & 60 {from server} to determine the type of endpoint.

    If manual CoA is working in AT but not in your policy, that points to a policy config.

    ------------------------------
    Danny Jump
    "Passionate about CPPM"
    ------------------------------



  • 5.  RE: Clearpass profiling issue

    Posted Dec 02, 2020 04:20 PM
    Hi Danny,
    The profiler and COA part is in my opinion part of the same solution.
    The workflow is that a new device authenticate to CP, gets COA & is profiled. Second auth works on endpoint database authentication.

    The device doesn't get to the profiling part of the service. It gets the default action which is the GUEST vlan. The service is just a default wires MAC auth.

    Regards,

    ------------------------------
    Thomas Willems
    ------------------------------



  • 6.  RE: Clearpass profiling issue

    Posted Dec 02, 2020 10:16 PM
    Going back to the profiling, are, you planning to use DHCP as your preferred profiling method?

    If YES, then the same Q from above applies please re DHCP messages, if not DHCP how are you planning to profile the devices?

    ------------------------------
    Danny Jump
    "Passionate about CPPM"
    ------------------------------



  • 7.  RE: Clearpass profiling issue

    Posted Dec 03, 2020 10:28 AM
    Hi Danny,
    I do uses DHCP profiling like my preffered method, no DHCP helper is on the GUEST VLAN, but if I check the MAC adres in the Endpoint database, I could see the right attributes are present.

    ------------------------------
    Thomas Willems
    ------------------------------



  • 8.  RE: Clearpass profiling issue

    Posted Dec 03, 2020 10:08 AM
    If I summarize correctly:
    - client connects to wired port
    - MAC auth is happening with Profiling option in the service is enabled
    - because it is unknown the enforcement will be the Guest VLAN and a captive portal redirect
    At that point, do you get profiling information in? Does Access tracker show the device type next to the client MAC?
    Is DHCP ip helper configured from the Guest VLAN?
    You don't see an automatic CoA when new profiling data comes it?
    Do you see the CoA tab in Access Tracker? That should appear if a CoA is triggered, by profiler or something else.
    In this situation, you can successfully trigger a manual CoA?

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC.
    ------------------------------



  • 9.  RE: Clearpass profiling issue

    Posted Dec 03, 2020 10:27 AM
    Herman,

    You are correct, just Guest VLAN, not captive portal (isn't configured).
    The GUEST VLAN doesn't have any DHCP IP helper, but if I check the MAC in the endpoint database, the right attributes are present.
    I don't see any automatic COA.
    I can trigger an manual COA, but that doesn't do the trick either.

    ------------------------------
    Thomas Willems
    ------------------------------



  • 10.  RE: Clearpass profiling issue

    Posted Dec 04, 2020 07:48 AM
    Can you share your policy and access tracker results? Alternatively, it may be good to work with your partner or Aruba support to interactively troubleshoot your service and policy. There is not enough information in your requests and all efforts above are just based on guessing what is the situation, while in many of these cases the solution is in a small detail.

    If you don't have an IP helper in the Guest VLAN, an automatic CoA will not be triggered as there will not get in new profiling data.
    If unknown/unprofiled devices end up in the Guest VLAN, make sure you have an ip-helper or dhcp relay configured towards your ClearPass for that subnet.
    If your endpoint has already the correct details, like device type/name, you should check your enforcement policy why it is not sending out the correct enforcement profile.

    The Wired Policy Enforcement guide, as available from https://www.arubanetworks.com/clearpassdocs would provide guidance as well. It is for different switches, so the actual enforcement may be slightly different, but workflows are very similar.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC.
    ------------------------------



  • 11.  RE: Clearpass profiling issue

    Posted Dec 05, 2020 04:10 AM
    Good morning,

    I already have a case running, but the engineer doesn't seems to find the solution.

    I will first test with a VLAN where there is DHCP relay. Will keep you posted.

    Kind regards,


    ------------------------------
    Thomas Willems
    ------------------------------