Security

 View Only
Expand all | Collapse all

DHCP fingerprinting and CPPM extensions

This thread has been viewed 2 times
  • 1.  DHCP fingerprinting and CPPM extensions

    Posted Oct 02, 2018 08:09 AM

    For a long tike nowe we've been having "discussions" with our security team re dhcp forwarding of vlans that pass through our checkpoint firewall. 

    They say its working we say clearpass can't profile anything that comes from our "portal" vlans - the place a device drops into if we can't figure out what it is.

    Annoyingly, for all our vlans that do not pass via the firewall I can see dhcp fingerprinting working o.k... If I delete an endpoint entry next reauth I can see it cioming back and being fingerprinted o.k. ... just not for devices on our portal vlans .

     

    Because we use named vlans when dropping a device into the portal vlan  ( name=portal_vlan) I didn't notice that the address space we use for portal_vlan is 172.17.0.0/16 .... which of course is the address space used for clearpass extensions. 

     

    Would this have any effect on processing dhcp fingerprinting ?

     

    I've just changed the extension address range to be 192.168.0.0/16 and restarted the extensions service on our test service... but it doesn't seem to have made any difference.

     

     

     



  • 2.  RE: DHCP fingerprinting and CPPM extensions

    Posted Oct 09, 2018 03:47 AM

    I assume the firewall i forwarding the DHCP packets to your CPPM, does it have several IPs ? are your sure the relaying on the firewall is correct ?

     

    A test would be to relay to a machine running wireshark or similar to actually see that the DHCP packets are passing the firewall.

     

    If there are VLAN routing involved you will probably need to forward the packets on your switch as well.