Security

 View Only
  • 1.  Removing individual MAC address from Static Host List

    Posted Oct 24, 2023 12:13 PM

    Hi, 

    I am fairly new to the Clearpss, I would appreciate if someone can advise how to safely remote individual mac address from Static Host group. 

    There is a way to delete a mac from Configuration Identity Endpoints but this seems to be already authenticated/profiled endpoint and not sure if I delete from there it will also go away from Static Host list group and the same MAC may not able to authenticate thereafter.

    Thanks in advance.

     



  • 2.  RE: Removing individual MAC address from Static Host List

    Posted Oct 25, 2023 09:50 AM

    This all depends on your setup of Clearpass.  You will have to look at the Enforcement Policy and Role mapping details to see what is setup.


    Here is an example of my setup and this is not the same as your setup.  You will need to view the details of what you have setup.

    I use static host lists to map to roles:
    Configuration -> Role Mappings -> 'XXXXXX- MAC-RoleMapping'

    (Radius:IETF:Calling-Station-Id  BELONGS_TO_GROUP  MAC-AUTH - XXXXXX-PRINTER) ROLE-MAC-AUTH-PRINTER


    Configuration -> Enforcement -> Policies -> XXXXXX- Aruba-Wireless-MAC-Enforcement

    Default Profile:
    [Deny Access Profile]
    (Tips:Role  EQUALS  ROLE-MAC-AUTH-PRINTER) WIRELESS-VLAN-PRINTER

     

    ^In the example above, I am setting a role based on the device being part of a SHL called MAC-AUTH - XXXXXX-PRINTER.  I then match on the role and use the enforcement profile WIRELESS-VLAN-PRINTER.  If I were to remove a mac from the Printer SHL, then it would not get the role anymore and hit the default profile of Deny Access.

    This is just an example of what I have setup and your setup may be very different.  It is possible that you might be setting a role based on the device being profiled/being in the endpoint database or some other attribute.  I can not know the answer to your question without looking at your setup.

    If you are really unsure, open a ticket with TAC and have them run through what you have setup and have them help you out.




  • 3.  RE: Removing individual MAC address from Static Host List

    Posted Oct 27, 2023 10:04 AM

    Hi,

    Thanks for taking your time to reply on this. I'm actually looking for removing mac from static host list directly.. 




  • 4.  RE: Removing individual MAC address from Static Host List

    Posted Oct 27, 2023 09:54 AM

    You can remove entries from a static host list by editing it and press the trashbin for the entry you want to remove:

    You can find the Static Host Lists under Configuration -> Identity:

    If you are not familiar with ClearPass, be warned that you can seriously break things if you perform a bad action.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: Removing individual MAC address from Static Host List

    Posted Oct 27, 2023 10:09 AM

    Hi Herman,

    Thanks for your reply. I used to delete mac from the same way you suggested, but in my case I have more than 800 mac address and it is hard to scroll down and find the exact mac address I wanted to delete from such a big list.

    I see that there's a way to do from Configuration Identity Endpoints (here we can probably do search the mac and delete) but not sure this will not allow for the same mac address to reauthenticate again.?.

    The issue that I was by mistake I added same mac address on two static group lists and I want to delete it from one group list. 




  • 6.  RE: Removing individual MAC address from Static Host List

    Posted Oct 27, 2023 04:35 PM

    Depends on how your setup is.  The Endpoint database and the static host list are two different things.

    If the policy is allowing endpoints in the endpoint database to authenticate, then deleting it from the endpoint database would prevent it from authenticating.

    If the policy is allow endpoints in the static host list to authenticate, then deleting it from the static host list will prevent it from authenticating.

    Since you have a static host list, I am assuming that is what is allowing it to authenticate but again, I have no idea what your setup is.  There are so many different ways that you can have something authenticate and I can not tell you without looking at what you have setup.

    My assumption is that you have that static host list for a reason.  If it is in there, my assumption is that the static host list is what is allowing the authentication but again ASSUMPTION.




  • 7.  RE: Removing individual MAC address from Static Host List

    Posted Oct 31, 2023 11:24 AM

    It may be better to get rid of your static host lists and change to the endpoint database with attributes there. Static host lists are known to not scale very well, and are also deprecated because of that.

    Removing a device from the endpoint database is separate from static host lists, so it will be added again automatically to the endpoint database when the client reauthenticates.

    What are you trying to do with the SHL? It may help to find the better alternative if we understand better what you try to achieve.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------