Security

 View Only
  • 1.  Sending Email as part of enforcement profile

    Posted Jun 19, 2025 06:27 AM

    Dear Experts, 

    Using Clearpass 6.11 (patch 11)

    I have a requirement where customer needs to send email alert when the device authentication fails. I know sending email for every failed auth is not feasible but they are targetting some particular scenarios, for now i want to know is it possible? i recall we could configure endpoint context servers and use tht in enfor profiles. I checked and tried steps given by Victor in below post

    https://community.arubanetworks.com/discussion/it-is-possible-with-clearpass-to-do-this

    However i cannot see the tabs as shown below, they are not appearing in my case.  To be clear, i am adding a new context server from Administration>External Servers>Endpoint context servers -> Add New



    ------------------------------
    Owais101
    ------------------------------


  • 2.  RE: Sending Email as part of enforcement profile

    Posted Jun 19, 2025 11:58 AM

    What you are looking for are Context Server Actions under Administration / Dictionaries.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 3.  RE: Sending Email as part of enforcement profile

    Posted Jun 19, 2025 05:03 PM

    Dear Gorazd, 

    Thank you for pointing in the right direction but i am not able to get it to work. I am currently using smtp.gmail.com and able to send the emails from CPPM successfuly. However i cannot send email upon successful user auth (via 802.1x) as part of customer requirement. I have followed the exact same steps as mentioned in below link

    https://community.arubanetworks.com/discussion/send-email-in-enforcement-policy

    1) i chose localhost but it didnt work

    2) i created mail.google.com and used that as target server, didnt work 

    3) i tried this link (https://community.arubanetworks.com/community-home/librarydocuments/viewdocument?DocumentKey=cf228234-2ff1-4e03-b952-554cc67c02f2&CommunityKey=3dd64143-3ac3-4152-9abd-06dc0b4ecdd1&tab=librarydocuments) but as soon as i click on validate, it gives me the error "

    Unable to reach OAuth2 server" 

    Any idea do i need to create any other service to make it work? i am using 6.11.11



    ------------------------------
    Owais101
    ------------------------------



  • 4.  RE: Sending Email as part of enforcement profile

    Posted Aug 29, 2025 09:53 PM

    using 3),  your OAuth2 Resource URL should include "/api/oath"




    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 5.  RE: Sending Email as part of enforcement profile

    Posted Aug 31, 2025 09:04 AM

    Hello,

    I would like to know how I can configure ClearPass to send an email notification when a device is placed in quarantine by the OnGuard agent.

    For example, when OnGuard detects a non-compliant endpoint and ClearPass enforces the quarantine role, I would like ClearPass to automatically send an email to our IT/security team so they can proactively take action based on the endpoint's status.

    Is there a recommended configuration or best practice for setting up these quarantine email notifications in ClearPass?

    Thank you in advance.

    -------------------------------------------