Security

 View Only
Expand all | Collapse all

OnGuard Persistent Agent – Restrict posture checks to corporate SSID/VLAN only

This thread has been viewed 9 times
  • 1.  OnGuard Persistent Agent – Restrict posture checks to corporate SSID/VLAN only

    Posted Sep 07, 2025 10:08 PM

    I'm currently running ClearPass version 6.11.12 with OnGuard Persistent Agent deployed on corporate endpoints. The requirement is to enforce posture checks only when the client connects to the specific SSID/VLAN dedicated for posture validation (for example, the corporate SSID that integrates with ClearPass).

    However, from my understanding, the OnGuard agent can attempt posture checks on any network where the device is connected. My concern is whether this behavior can be limited.

    • Is it possible to configure the OnGuard agent (Persistent Agent) so that it performs posture checks only on the defined network (SSID/VLAN)?

    • Or will the agent always try to perform posture checks regardless of which network the endpoint connects to (home Wi-Fi, guest network, etc.)?

    • If this configuration is possible, where should it be enforced: in the Agent Profile, in the ClearPass Policy Manager Enforcement, or within the Network Access Device role assignment?

    Any guidance or best practices would be appreciated, since we want to avoid unnecessary posture checks when users are outside the corporate network.



    -------------------------------------------


  • 2.  RE: OnGuard Persistent Agent – Restrict posture checks to corporate SSID/VLAN only

    Posted Sep 08, 2025 09:42 AM

    The persistent agent is always going to run.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: OnGuard Persistent Agent – Restrict posture checks to corporate SSID/VLAN only

    Posted Sep 11, 2025 09:37 AM

    Haven't tried, but under Onguard Settings - Policy Manager Zones, you can override/force the IP/FQDN that the OnGuard agent will connect to. You may set it to an FQDN that's only internally resolvable. Or you can add only your corporate IP space in the default zone, where it may be (again untested) that the client will only report if it's in one of those IP subnets.

    Doesn't help if people at home or on the road use an IP that overlaps with your corporate range. Also may not stop the client from enforcing/performing checks.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------