SlideShare a Scribd company logo
2
Most read
7
Most read
12
Most read
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc. All rights
reserved
Advanced ClearPass - Workshop
Ashwath Murthy
June 2014
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
Agenda
• Discover  Monitor  Secure
• Network Security with ClearPass
• Deploying NAC with OnGuard
– Wired & Wireless NAC
– NAC – Best Practices
• TACACS+ for Network Device Security
• BYOD with Onboard
• Monitoring & Troubleshooting
Network Security with ClearPass
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
Discover  Monitor  Secure
• Discover
– Discover via profiling
• DHCP
• Non-DHCP
• Monitor
– Enable policies in “Monitor” Mode
• Secure
– Secure Wireless, Wired and VPNs
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
Network Security – Wired & Wireless
• Strong Security with 802.1X
– Enterprise Users
– Need for strong, session-driven security
• Captive Portals for Guest Access
– Transient users such as Guests, Contractors
– Limited network access zones
– Weaker security settings
• BYOD with unique credentials
– Employee BYO Devices
– Non-IT assets
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
Network Security – Wired & Wireless
• Authenticate & Authorize
– Certificates
– UserID/Password
– Tokens/OTP
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
Network Security – Wired
• Enable 802.1X on access ports
• Allow fall-back to less secure modes of access
– Limit network access
• Segregate responsibilities
– Aruba Roles
– VLANs
– ACLs/dACLs
– Upstream enforcement with L3-L7 firewalls such as Palo Alto
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
Network Security – Wired
• But I have older switches that do not support
802.1X!
• Use SNMP to enforce port status
– Set VLANs and Session-Timeout values
– “Bounce” a port
– Send LinkUp/LinkDown and MAC Notification Traps to
ClearPass
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
Network Security – Wired
• How will ClearPass set VLANs using SNMP?
– Using the standard If-MIB
• SNMP VLANs and MAC Authentication? What!?
– Redirect the user to a captive portal after MAB
– Authenticate & Authorize with the captive portal
Wireless Access Security
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
Wireless – Enterprise
• Enable 802.1X – WPA/WPA2 Enterprise
– Session-based keys for secure connectivity
– Terminate EAP on ClearPass – infrastructure is EAP-
agnostic
– Consistent user experience and security practice across
deployments
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
Wireless – Guest
• Enable Guest Access/MAC Authentication
– This can be combined with a WPA/WPA2 Passphrase
– Networks are inherently open unless secured!
– Strong access restrictions
• Tunneled VLANs
• Stateful ACLs
• DPI/Application Monitoring
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
Wireless – BYOD
• What about BYO Devices?
• BYO Devices on the enterprise network
– Deliver certificates to BYO Devices using Onboard
– Segregate responsibilities by identifying BYO Devices
– Control device life cycle
• BYO Devices on the guest network
– Devices use a segregated guest network
– Limited network access
– Challenges with device life cycle
NAC is Back, Baby!!!
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
NAC
• Agent Types – Persistent/Dissolvable
• Posture Assessment – Windows, Mac, Linux
– Agent Types
– Health Check Options
• Enforcement Options
– Role-based
– Application-based
– To remediate, or not to remediate?
• Wired NAC vs. Wireless NAC
• NAC for VPN
• Best Practices, Thoughts
TACACS+ for Network Devices
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
TACACS+
• TACACS+ Authentication
– Console, Shell, UI Login
• TACACS+ Authorization
– Command Authorization
– Command Levels
• TACACS+ Accounting
– Accounting & Audit Trails
– Authorization vs. Accounting
• Vendor Specifics
– TACACS+ Dictionaries
BYOD with Onboard
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
BYOD with Onboard
• CA Settings
– Stand-alone CA
– Intermediate CA
– ADCS
• Configuration Payloads
– iOS & Mac OS X
– Microsoft Windows
– Android
• Provisioning Settings
– TLS? PEAP-MSCHAPv2?
– Security Settings
– Certificate Renewal
Monitoring & Troubleshooting
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
Monitoring & Troubleshooting
• Monitoring on ClearPass
– Access Tracker
• Alerts Tab
• Accounting Tab
• “Show Logs”
– Analysis & Trending
• Drill Down
– Policy Simulation
– Authentication Simulation
– Insight
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
Monitoring & Troubleshooting
• External Monitoring
– SIEM with Syslog/APIs
– SNMP
– SQL Access
#AirheadsLocal

More Related Content

PDF
Aruba ClearPass Guest 6.3 User Guide
PPT
Access Management with Aruba ClearPass
PPTX
Advanced Aruba ClearPass Workshop
PPTX
EMEA Airheads - AP Discovery Logic and AP Deployment
PPTX
Advanced Access Management with Aruba ClearPass #AirheadsConf Italy
PPTX
EMEA Airheads- ArubaOS - High availability with AP Fast Failover
PDF
Aruba Networks - Overview ClearPass
PDF
Aruba ClearPass Guest 6.3 User Guide
Access Management with Aruba ClearPass
Advanced Aruba ClearPass Workshop
EMEA Airheads - AP Discovery Logic and AP Deployment
Advanced Access Management with Aruba ClearPass #AirheadsConf Italy
EMEA Airheads- ArubaOS - High availability with AP Fast Failover
Aruba Networks - Overview ClearPass

What's hot (20)

PPTX
ClearPass design scenarios that solve the toughest security policy requirements
PDF
Managing and Optimizing RF Spectrum for Aruba WLANs
PDF
Aruba clearpass ebook_chpt1_final
PPTX
Access Management with Aruba ClearPass
PDF
PPTX
EMEA Airheads- Aruba Central with Instant AP
PPTX
EMEA Airheads- ArubaOS - Cluster Manager
PPTX
EMEA Airheads - What does AirMatch do differently?v2
PDF
ClearPass Overview
PPTX
EMEA Airheads - Configuring different APIs in Aruba 8.x
PDF
Clear pass policy manager advanced_ashwath murthy
PPTX
Airheads Tech Talks: Advanced Clustering in AOS 8.x
PDF
Base Designs Lab Setup for Validated Reference Design
PPTX
Large scale, distributed access management deployment with aruba clear pass
PPTX
Enhance network security with Multi-Factor Authentication for BYOD and guest ...
PPTX
PPTX
Enabling AirPrint & AirPlay on Your Network
PPTX
Aruba WLANs 101 and design fundamentals
PPTX
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
ClearPass design scenarios that solve the toughest security policy requirements
Managing and Optimizing RF Spectrum for Aruba WLANs
Aruba clearpass ebook_chpt1_final
Access Management with Aruba ClearPass
EMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- ArubaOS - Cluster Manager
EMEA Airheads - What does AirMatch do differently?v2
ClearPass Overview
EMEA Airheads - Configuring different APIs in Aruba 8.x
Clear pass policy manager advanced_ashwath murthy
Airheads Tech Talks: Advanced Clustering in AOS 8.x
Base Designs Lab Setup for Validated Reference Design
Large scale, distributed access management deployment with aruba clear pass
Enhance network security with Multi-Factor Authentication for BYOD and guest ...
Enabling AirPrint & AirPlay on Your Network
Aruba WLANs 101 and design fundamentals
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Ad

Viewers also liked (20)

PPTX
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
PPTX
Aruba ClearPass Exchange Deep Dive
PPTX
PPTX
802.11ac Migration - Airheads Local
PPTX
EMEA Airheads- Instant AP- APP REF and Mixed IAP Cluster deployments
PDF
EMEA Airheads- Instant AP traffic optimization
POTX
Network management with Aruba AirWave
PDF
RF planning for high-densities of mobile devices and bandwidth-hungry mobile ...
PDF
EMEA Airheads- Troubleshooting 802.1x issues
PDF
EMEA Airheads – Aruba controller features used to optimize performance
PPTX
EMEA Airheads ClearPass guest with MAC- caching using Time Source
PPTX
RF characteristics and radio fundamentals
PPTX
Getting the most out of the Aruba Policy Enforcement Firewall
PDF
Fast-track your career by going from wireless to mobility engineer
PDF
EMEA Airheads- Aruba OS- Mobile First Platform– Aruba OS 8.0 introduction
PPTX
Wi-Fi Security Fundamentals
POTX
Packets never lie: An in-depth overview of 802.11 frames
PPTX
A-to-Z design guide for the all-wireless workplace
PDF
EMEA Airheads- Instant AP- Instant AP Best Practice Configuration
PPTX
Mobile First Healthcare: Chris Kozup Aruba (HPE)
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
Aruba ClearPass Exchange Deep Dive
802.11ac Migration - Airheads Local
EMEA Airheads- Instant AP- APP REF and Mixed IAP Cluster deployments
EMEA Airheads- Instant AP traffic optimization
Network management with Aruba AirWave
RF planning for high-densities of mobile devices and bandwidth-hungry mobile ...
EMEA Airheads- Troubleshooting 802.1x issues
EMEA Airheads – Aruba controller features used to optimize performance
EMEA Airheads ClearPass guest with MAC- caching using Time Source
RF characteristics and radio fundamentals
Getting the most out of the Aruba Policy Enforcement Firewall
Fast-track your career by going from wireless to mobility engineer
EMEA Airheads- Aruba OS- Mobile First Platform– Aruba OS 8.0 introduction
Wi-Fi Security Fundamentals
Packets never lie: An in-depth overview of 802.11 frames
A-to-Z design guide for the all-wireless workplace
EMEA Airheads- Instant AP- Instant AP Best Practice Configuration
Mobile First Healthcare: Chris Kozup Aruba (HPE)
Ad

Similar to Advanced ClearPass Workshop (20)

PPTX
Remote & Branch Networking Fundamentals #AirheadsConf Italy
PPTX
Access Management with Aruba ClearPass #AirheadsConf Italy
PPTX
Unified access with Aruba Mobility Access Switches – Live Demo
PDF
NFV & SDN Customer Deployments
PDF
Instant overview gokul_rajagopalan
PDF
ARUBA - Remote Branch-networking-fundamentals-2014
PPTX
Shanghai Breakout: Access Management with Aruba ClearPass
PDF
2012 ah apj wlan security fundamentals
PPTX
Sydney UC - February 2015
PPTX
Defining Advanced AAA Policies for Access Networks
PPTX
ClearPass_Design Info.pptx
PPTX
Real-world 802.1X Deployment Challenges
PDF
2012 ah vegas guest access fundamentals
PPTX
PDF
Security advanced rich langston_jon green
PDF
3 air wave practical workshop_mike bruno_matt sidhu
PPTX
Network Management with Aruba Airwave #AirheadsConf Italy
PDF
Next generation remote networks aruba instant gokul rajagopalan
PDF
Breakout - Airheads Macau 2013 - ClearPass Access Management Basics
Remote & Branch Networking Fundamentals #AirheadsConf Italy
Access Management with Aruba ClearPass #AirheadsConf Italy
Unified access with Aruba Mobility Access Switches – Live Demo
NFV & SDN Customer Deployments
Instant overview gokul_rajagopalan
ARUBA - Remote Branch-networking-fundamentals-2014
Shanghai Breakout: Access Management with Aruba ClearPass
2012 ah apj wlan security fundamentals
Sydney UC - February 2015
Defining Advanced AAA Policies for Access Networks
ClearPass_Design Info.pptx
Real-world 802.1X Deployment Challenges
2012 ah vegas guest access fundamentals
Security advanced rich langston_jon green
3 air wave practical workshop_mike bruno_matt sidhu
Network Management with Aruba Airwave #AirheadsConf Italy
Next generation remote networks aruba instant gokul rajagopalan
Breakout - Airheads Macau 2013 - ClearPass Access Management Basics

More from Aruba, a Hewlett Packard Enterprise company (20)

PPTX
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
PPTX
EMEA Airheads_ Advance Aruba Central
PPTX
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
PPTX
EMEA Airheads- Switch stacking_ ArubaOS Switch
PPTX
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
PPTX
PPTX
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
PPTX
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
PPTX
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
PPTX
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
PPTX
EMEA Airheads- Manage Devices at Branch Office (BOC)
PPTX
Airheads Meetups: 8400 Presentation
PPTX
Airheads Meetups: Ekahau Presentation
PPTX
Airheads Meetups- High density WLAN
PPTX
Airheads Meetups- Avans Hogeschool goes Aruba
PPTX
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
PPTX
EMEA Airheads - Multi zone ap and centralized image upgrade
PPT
Bringing up Aruba Mobility Master, Managed Device & Access Point
PPTX
EMEA Airheads How licensing works in Aruba OS 8.x
PPTX
EMEA Airheads- Aruba 8.x Architecture overview & UI Navigation
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
EMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Manage Devices at Branch Office (BOC)
Airheads Meetups: 8400 Presentation
Airheads Meetups: Ekahau Presentation
Airheads Meetups- High density WLAN
Airheads Meetups- Avans Hogeschool goes Aruba
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
EMEA Airheads - Multi zone ap and centralized image upgrade
Bringing up Aruba Mobility Master, Managed Device & Access Point
EMEA Airheads How licensing works in Aruba OS 8.x
EMEA Airheads- Aruba 8.x Architecture overview & UI Navigation

Recently uploaded (20)

DOCX
The AUB Centre for AI in Media Proposal.docx
PPTX
Cloud computing and distributed systems.
PDF
Machine learning based COVID-19 study performance prediction
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
Spectroscopy.pptx food analysis technology
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
The AUB Centre for AI in Media Proposal.docx
Cloud computing and distributed systems.
Machine learning based COVID-19 study performance prediction
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
“AI and Expert System Decision Support & Business Intelligence Systems”
Chapter 3 Spatial Domain Image Processing.pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Mobile App Security Testing_ A Comprehensive Guide.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
The Rise and Fall of 3GPP – Time for a Sabbatical?
Spectroscopy.pptx food analysis technology
NewMind AI Weekly Chronicles - August'25 Week I
Advanced methodologies resolving dimensionality complications for autism neur...
Spectral efficient network and resource selection model in 5G networks
20250228 LYD VKU AI Blended-Learning.pptx
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...

Advanced ClearPass Workshop

  • 1. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Advanced ClearPass - Workshop Ashwath Murthy June 2014
  • 2. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Agenda • Discover  Monitor  Secure • Network Security with ClearPass • Deploying NAC with OnGuard – Wired & Wireless NAC – NAC – Best Practices • TACACS+ for Network Device Security • BYOD with Onboard • Monitoring & Troubleshooting
  • 4. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Discover  Monitor  Secure • Discover – Discover via profiling • DHCP • Non-DHCP • Monitor – Enable policies in “Monitor” Mode • Secure – Secure Wireless, Wired and VPNs
  • 5. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Network Security – Wired & Wireless • Strong Security with 802.1X – Enterprise Users – Need for strong, session-driven security • Captive Portals for Guest Access – Transient users such as Guests, Contractors – Limited network access zones – Weaker security settings • BYOD with unique credentials – Employee BYO Devices – Non-IT assets
  • 6. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Network Security – Wired & Wireless • Authenticate & Authorize – Certificates – UserID/Password – Tokens/OTP
  • 7. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Network Security – Wired • Enable 802.1X on access ports • Allow fall-back to less secure modes of access – Limit network access • Segregate responsibilities – Aruba Roles – VLANs – ACLs/dACLs – Upstream enforcement with L3-L7 firewalls such as Palo Alto
  • 8. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Network Security – Wired • But I have older switches that do not support 802.1X! • Use SNMP to enforce port status – Set VLANs and Session-Timeout values – “Bounce” a port – Send LinkUp/LinkDown and MAC Notification Traps to ClearPass
  • 9. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Network Security – Wired • How will ClearPass set VLANs using SNMP? – Using the standard If-MIB • SNMP VLANs and MAC Authentication? What!? – Redirect the user to a captive portal after MAB – Authenticate & Authorize with the captive portal
  • 11. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Wireless – Enterprise • Enable 802.1X – WPA/WPA2 Enterprise – Session-based keys for secure connectivity – Terminate EAP on ClearPass – infrastructure is EAP- agnostic – Consistent user experience and security practice across deployments
  • 12. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Wireless – Guest • Enable Guest Access/MAC Authentication – This can be combined with a WPA/WPA2 Passphrase – Networks are inherently open unless secured! – Strong access restrictions • Tunneled VLANs • Stateful ACLs • DPI/Application Monitoring
  • 13. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Wireless – BYOD • What about BYO Devices? • BYO Devices on the enterprise network – Deliver certificates to BYO Devices using Onboard – Segregate responsibilities by identifying BYO Devices – Control device life cycle • BYO Devices on the guest network – Devices use a segregated guest network – Limited network access – Challenges with device life cycle
  • 14. NAC is Back, Baby!!!
  • 15. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved NAC • Agent Types – Persistent/Dissolvable • Posture Assessment – Windows, Mac, Linux – Agent Types – Health Check Options • Enforcement Options – Role-based – Application-based – To remediate, or not to remediate? • Wired NAC vs. Wireless NAC • NAC for VPN • Best Practices, Thoughts
  • 17. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved TACACS+ • TACACS+ Authentication – Console, Shell, UI Login • TACACS+ Authorization – Command Authorization – Command Levels • TACACS+ Accounting – Accounting & Audit Trails – Authorization vs. Accounting • Vendor Specifics – TACACS+ Dictionaries
  • 19. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved BYOD with Onboard • CA Settings – Stand-alone CA – Intermediate CA – ADCS • Configuration Payloads – iOS & Mac OS X – Microsoft Windows – Android • Provisioning Settings – TLS? PEAP-MSCHAPv2? – Security Settings – Certificate Renewal
  • 21. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Monitoring & Troubleshooting • Monitoring on ClearPass – Access Tracker • Alerts Tab • Accounting Tab • “Show Logs” – Analysis & Trending • Drill Down – Policy Simulation – Authentication Simulation – Insight
  • 22. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Monitoring & Troubleshooting • External Monitoring – SIEM with Syslog/APIs – SNMP – SQL Access

Editor's Notes

  • #5: 30:24 – 32:44
  • #6: 30:24 – 32:44
  • #7: 30:24 – 32:44
  • #8: 30:24 – 32:44
  • #9: 30:24 – 32:44
  • #10: 30:24 – 32:44
  • #12: 30:24 – 32:44
  • #13: 30:24 – 32:44
  • #14: 30:24 – 32:44
  • #16: 30:24 – 32:44
  • #18: 30:24 – 32:44
  • #20: 30:24 – 32:44
  • #22: 30:24 – 32:44
  • #23: 30:24 – 32:44