Security

 View Only
  • 1.  ClearPass Synchronization Service

    Posted Jul 21, 2023 04:03 AM

    Hello Team, We are trying to replicate configuration between two different clusters. While exploring options, I came across ClearPass Synchronization Service. Unfortunately, I am not finding any relevant information about how it actually works. Can someone please confirm if you guys have ever used it? Will it sync local user accounts and guest accounts with passwords between the two different clusters?

    ClearPass synchronization service

    HPE Aruba Networking remove preview
    ClearPass synchronization service
    Save time and keep your network access secure across multiple Aruba ClearPass clusters with our purpose-built tool.
    View this on HPE Aruba Networking >



  • 2.  RE: ClearPass Synchronization Service

    Posted Jul 21, 2023 04:08 AM

    According to the datasheet you shared: yes it will synchronize accounts:

    This tool enables efficient sync of configuration, user, guest, and device objects across individual CPPM clusters.

    CPPM Sync is a professional service, and it will be configured for you:

    To find out more about how our ClearPass Synchronization Service can dramatically simplify your approach to managing ClearPass clusters across numerous geographically remote sites, please contact Aruba Sales. Request to see a demonstration walk-through of the CPPMSync tool.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: ClearPass Synchronization Service

    Posted Jul 21, 2023 05:15 AM

    Thank you for the quick response Herman. I am not really sure if I can relay on the Document to propose this solution to the customer. If I can get a confirmation from Aruba or anyone who implemented this solution, That'll be a great help.

    We are unable to conclude this with HPE professional services so far.

    Thank you,

    Bharath Kumar.




  • 4.  RE: ClearPass Synchronization Service

    Posted Jul 21, 2023 09:09 AM

    Hi

    What is your exact use case to replicate data between the clusters?

    I have been looking at the CPPM Sync service a bit for a customer running three clusters today, but they had six clusters a few years ago. The idea in that case was to replicate configuration to eliminate the need to do configuration changes on multiple clusters when new rules where added.

    I concluded that the CPPM Sync Service is too expensive to use in such scenario, but it will for sure solve some cases if you have a lot of clusters, tens or hundreds, where you need to replicate the configuration.

    With the customer I now have regional configurations for the different clusters and the configuration have some minor differences as the servers are connecting to the nearest AD domain controllers etc. I do not have a need to replicate local users, as authentication and authorization is done with AD users, There are also no need to replicate guest accounts in this case as it's "unlikely" that a guest user registered in the US will appear within a few hours in an European office.

    I can see a use case for the Sync service for another customer where they would like the Staging and Production environments to be identical. In this case it would be nice to only push the validated configuration from the Staging cluster to the Production cluster and not do any administation and configuration changes in production. But the price tag is to high to implement this.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP 2023, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACDP , ACEP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 5.  RE: ClearPass Synchronization Service

    Posted Jul 21, 2023 09:44 AM

    Hello Jonas,

    The customer is creating Credentials (Local User accounts and Guest Accounts using API's from a centralized portal globally).  This setup is only pointed to one of the current prod cluster. They acquired a new entity where they want to replicate the same credentials from Global Cluster to the new Cluster. Due to security reasons, They do not want to point the New Entity to their application for user creation  .

    Thank you,

    Bharath.




  • 6.  RE: ClearPass Synchronization Service

    Posted Jul 21, 2023 10:08 AM

    Hi Bharath

    In that case I agree that it would be nice to have the syncronization service.

    But considered the price tag I think it will be cheaper to develop the function inhouse, or together with an Aruba partner or representant from Aruba.

    I guess it's possible to get the needed function with the help of the API. But I'm not a developer so I don't have the knowledge on how to do this and how much work it will require.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP 2023, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACDP , ACEP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 7.  RE: ClearPass Synchronization Service

    Posted Jul 21, 2023 11:06 AM

    If that is the use-case, creating credentials in multiple clusters via the API, why not send that API call to 2 publishers instead of just the current one?

    CPPMSync sounds like over-kill for this scenario.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 8.  RE: ClearPass Synchronization Service

    Posted Jul 25, 2023 01:30 AM

    Hello Herman,

    They do not want to link the New entity with their Central User repository due to some security concerns. I am struggling to get the confirmation  regarding the Credential sync using CPPM Sync Extension from HPE sales/PS .

    I believe this is the only solution which can tackle our problem . 

    Thank you,

    Bharath.




  • 9.  RE: ClearPass Synchronization Service

    Posted Jul 28, 2023 07:29 AM

    Please send me a personal message with your contact details, location and who you normally speak with in Aruba or your partner. I'll see if I can get you connected with the right people.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------