SlideShare a Scribd company logo
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 1 #airheadsconf#airheadsconf
ClearPass Policy Manager – Advanced
Ashwath Murthy
03/15/2013
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 2 #airheadsconf
ClearPass – Policy Model
Authorization – What and Why?
Profile – How does it work?
Clustering & Deployment
Q & A
Agenda
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 3 #airheadsconf#airheadsconf3
ClearPass Policy Model
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 4 #airheadsconf
•  What constitutes the policy model?
•  How does it work?
•  What are the interactions between various
components?
•  How does the policy model affect configuration
& deployment?
ClearPass Policy Model
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 5 #airheadsconf
ClearPass Policy Model
Policy
Identity
Health
Device
Conditions
• Role
• Department
• Group
•  AV, AS, FW
• Registry Keys
• Services…
• Device type,
status, health
• Address, O/S
• Corp. Owned
• Time
• Location
• Day of Week
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 6 #airheadsconf
What’s the flow?
Authenticate
• Valid Authentication
Authorize
• Find Out What’s Allowed
Associate
Context
• Device, Time, Location, Posture
Enforce on
NAS
• Roles, ACLs, VLANs
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 7 #airheadsconf
What Are The Interactions?
RADIUS Server – Authenticate
Policy Server – Authorize
Policy Server – Associate Context
Policy Server – Decision Tree
RADIUS Server – Enforce
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 8 #airheadsconf
Service Flow – 802.1X
Layer 2
RADIUS
Request
Layer 2
Authentication
Layer 2
Authorization
Layer 2
Role
Derivation
Layer 2
RADIUS
Enforcement
Layer 3
Profile
Layer 2
NAP
Layer 3
OnGuard
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 9 #airheadsconf
•  Layer 2 Authentications are completed first
–  Full Authorization
–  Role Derivation
–  NAP (if enabled)
–  Layer 2 Enforcement
•  Layer 3 : Profile next
–  DHCP Request, DHCP Offer
–  RFC 3576 – Change of Authorization
•  Another Layer 2 authentication!
–  No RFC 3576 message if “fingerprint” does not change
•  Layer 3 : Collect Posture last (OnGuard)
–  Posture over HTTPS
–  RFC 3576 based on policy
•  Another Layer 2 authentication!
Service Flow – Implications
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 10 #airheadsconf#airheadsconf10
Authorization – What and Why?
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 11 #airheadsconf
•  Authentication vs. Authorization
•  Authorization & ClearPass
•  Use Cases
Authorization – What and Why?
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 12 #airheadsconf
Authorization & ClearPass
•  “Authorization” Sources in ClearPass
–  Where do I find them?
–  How do I use them?
–  How often does ClearPass talk to an authorization source?
–  What happens in case something goes wrong?
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 13 #airheadsconf
•  An “Authentication Source” is an “Authorization
Source”
–  RADIUS Server vs. Policy Server
Authorization Sources – Where?
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 14 #airheadsconf
Authorization Sources – How?
Authentication Sources
are automatic
Authorization Sources
Additional Authorization
Sources enabled
per Service
No Authorization unless
used in Roles!
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 15 #airheadsconf
Authorization Sources – How?
Authorize with
Active Directory
Authorize with
Profile Data
Rule Algorithm :
Evaluate All
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 16 #airheadsconf
•  Ok, great. But will ClearPass flood my AD with
authorization requests?
–  Authorization data is cached per user
–  New request made to fetch data once the cache expires
–  Cache timers can be tuned
Authorization – How?
Cache Timeout
Default: 10 hours
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 17 #airheadsconf
•  Got it
•  But I just made a bunch of changes on my AD.
Should I need to wait 10 hours?
–  Tune the cache timers
–  “Clear Cache” button on the Authentication Source
•  Wipes out cache for all users
–  “Save” button on the Authentication Source
•  Wipes out cache for all users
–  Restart Policy Server
•  BAD IDEA!!!
Authorization – How?
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 18 #airheadsconf
•  If an Authentication/Authorization Source is not
reachable
–  Configure Backup Servers
–  Configure Fail-Over Timeout
Authorization – Uh-Oh!
Fail-Over Timeout
Backup Servers
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 19 #airheadsconf
Use Cases – Mergers & Acquisitions
Active Directory
Domain –
avendasys.com
Active Directory
Domain –
arubanetworks.com
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 20 #airheadsconf
Authentication &
Authorization
Sources for TLS
Certificate Details
used for
Authorization
Enable Authorization –
Source specified in the
Service
Compare Certificate –
Source specified in the
Service
Use Cases – Certificates & TLS
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 21 #airheadsconf
•  LDAP/SQL Interface to Asset Databases
–  Key : MAC Address
–  Authorization Attributes
•  Ownership – Corporate vs. Personal
•  Compliance Status – In/Out of compliance
–  Identify corporate-owned non-Windows devices
Use Cases – Asset Databases
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 22 #airheadsconf#airheadsconf22
Profile – How does it work?
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 23 #airheadsconf
•  Profile & Network Data
•  Automatic Profile “upgrades”
•  Using Profile data in policy
•  Configuring Profile
–  DHCP? HTTP? SNMP?
•  Use Cases
Profile – How does it work?
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 24 #airheadsconf
•  What does ClearPass use to profile?
–  MAC OUIs
–  DHCP Request, DHCP Offer
–  HTTP User-Agent
–  MDM Fingerprints
–  Device Interrogation
–  SNMP/CDP/LLDP Data
Profile & Network Data
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 25 #airheadsconf
Fingerprint Updates
•  Subscribe to Fingerprint Updates
–  Automatic reclassification
–  Updated frequently
•  Tell Aruba!
–  Create policy exceptions
–  Grab fingerprints from UI
–  Send fingerprints to Aruba
–  Crowd-sourced, community oriented
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 26 #airheadsconf
•  Automatic 3-level categorization
–  Device Category, OS Family, Device Name
•  Using raw profile data
–  DHCP Data, HTTP User-Agent, SNMP Data
•  Role Mapping
–  What should I use?
•  Enforcement
–  How do I enforce?
–  What are the benefits?
Using Profile data in policy
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 27 #airheadsconf
•  DHCP Relay
–  Where should I setup DHCP relays?
•  Captive Portal Configuration
–  Is there a knob for this?
•  Reading SNMP Data
–  CDP
–  LLDP
–  HR MIB
–  SysDescr MIB
Configuring Profile – Network
Considerations
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 28 #airheadsconf
•  Policy – CEOs & iPads
•  Policy – “Headless” Devices
•  Visibility – Demystifying BYODs
Use Cases
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 29 #airheadsconf
Use Cases – CEOs & iPads
Assign Roles
Enforce Access
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 30 #airheadsconf
Use Cases – Headless Devices
Identify & Assign
Roles To Headless
Devices
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 31 #airheadsconf
Use Cases – Visibility
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 32 #airheadsconf#airheadsconf32
Clustering & Deployment
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 33 #airheadsconf
•  Clustering Technology
–  What’s replicated? What’s not?
•  Deploying ClearPass Clusters
–  Considerations
•  Operations & Maintenance
–  What happens when a ClearPass node is down?
–  Events & Alerts
–  Rescue & Recovery
Clustering & Deployment
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 34 #airheadsconf
•  What’s replicated?
–  All policy configuration elements
–  All Audit data
–  All identity store data
•  Guest Accounts, Endpoints, Profile data
–  Runtime Information
•  Authorization status, Posture status, Roles
•  Connectivity Information, NAS Details
–  Database replication on port# 5432 over SSL
–  Runtime replication on port# 443 over SSL
Clustering Technology
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 35 #airheadsconf
•  What’s not replicated?
–  Log files
–  Authentication Records
–  Accounting Records
–  System Events
–  System Monitor Data
Clustering Technology
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 36 #airheadsconf
•  How do they connect?
–  Requires IP connectivity (bi-directional)
•  Port # 5432 (Database over SSL)
•  Port# 80 (HTTP)
•  Port #443 (HTTPS)
•  Port #123 (NTP)
•  How much data should we expect to see
crossing the wire?
–  Only elements in the configuration database
–  First sync is a full database copy
–  Subsequent sync – Delta changes propagated
Clustering – Considerations
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 37 #airheadsconf
Clustering – Considerations
PUBLISHER
SUBSCRIBER
1
SUBSCRIBER
2
SUBSCRIBER
3
SUBSCRIBER
4
SUBSCRIBER
5
SUBSCRIBER
6
Hub & Spoke
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 38 #airheadsconf
Clustering – Considerations
CPPM – Publisher
DNS
DHCP
Identity
Stores
Main Data Center
Mid-size Branch
Regional Office
DMZ
CPPM
Subscriber
VM
CP Guest
CP Onboard
CPPM
Subscriber
CPPM
Subscriber
•  Central / Distributed Admin Domains
•  Redundancy/Load Balancing
•  Cluster wide licenses
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 39 #airheadsconf
•  What happens when a node goes down?
–  Operations
•  If Deployed Right – Nothing
•  RADIUS Backup settings on the NAS
–  If the Publisher goes down
•  No Database Writes Allowed!!
•  Promote a Subscriber to a Publisher
•  Resume configuration updates
Operations & Maintenance
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 40 #airheadsconf
•  How long before ClearPass figures out
something’s wrong?
–  24 hours before it automatically “drops” a node from the
cluster
–  Cluster Synchronization Warnings
•  1 event every hour x 24 hours = 24 events
–  CPU/Memory Usage Warnings  Every 2 Minutes
–  Server Certificate Warnings  Every 24 Hours
–  Service Alerts  Immediate
•  Email/SMS Alerts using Insight, Syslog & SNMP
Events & Alerts
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 41 #airheadsconf
•  Rescue & Recovery
–  Establish cluster connectivity
•  Database sync will ensue. Watch for “Last Sync Time”
–  Restore certificates
•  Server Certificates are not installed as a part of the sync
–  Restore log entries (If necessary)
•  Caveat : High disk activity for an extended period of time
–  Verify fail-back on the NAS
•  NAS fail-back timers should kick in
Operations & Maintenance
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 42 #airheadsconf#airheadsconf42
Q & A
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 43 #airheadsconf#airheadsconf
Thank You
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 44 #airheadsconf#airheadsconf44

More Related Content

PPTX
Access Management with Aruba ClearPass
PPTX
ClearPass design scenarios that solve the toughest security policy requirements
PDF
Aruba Networks - Overview ClearPass
PPTX
Advanced Aruba ClearPass Workshop
PDF
PDF
ClearPass Overview
PDF
Aruba clearpass ebook_chpt1_final
PPTX
EMEA Airheads - AP Discovery Logic and AP Deployment
Access Management with Aruba ClearPass
ClearPass design scenarios that solve the toughest security policy requirements
Aruba Networks - Overview ClearPass
Advanced Aruba ClearPass Workshop
ClearPass Overview
Aruba clearpass ebook_chpt1_final
EMEA Airheads - AP Discovery Logic and AP Deployment

What's hot (20)

PDF
Alphorm.com Microsoft AZURE
PPTX
Cisco Identity Services Engine (ISE)
PDF
Aruba ClearPass Guest 6.3 User Guide
PPTX
Enhance network security with Multi-Factor Authentication for BYOD and guest ...
PPTX
Advanced Access Management with Aruba ClearPass #AirheadsConf Italy
PPTX
EMEA Airheads- Aruba Central with Instant AP
PDF
Palo alto networks product overview
PPTX
Large scale, distributed access management deployment with aruba clear pass
PDF
Base Designs Lab Setup for Validated Reference Design
PDF
Understanding Cisco Next Generation SD-WAN Solution
PPTX
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
PPTX
Advanced ClearPass Workshop
PPT
Access Management with Aruba ClearPass
PDF
PDF
OWASP API Security Top 10 - API World
PPTX
Getting the most out of the Aruba Policy Enforcement Firewall
PDF
Alphorm.com Formation Microsoft Azure : Azure Active Directory 2021
PPTX
Palo Alto Networks 28.5.2013
PDF
ClearPass Policy Model - An Introduction
PDF
Understanding Azure AD
Alphorm.com Microsoft AZURE
Cisco Identity Services Engine (ISE)
Aruba ClearPass Guest 6.3 User Guide
Enhance network security with Multi-Factor Authentication for BYOD and guest ...
Advanced Access Management with Aruba ClearPass #AirheadsConf Italy
EMEA Airheads- Aruba Central with Instant AP
Palo alto networks product overview
Large scale, distributed access management deployment with aruba clear pass
Base Designs Lab Setup for Validated Reference Design
Understanding Cisco Next Generation SD-WAN Solution
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Advanced ClearPass Workshop
Access Management with Aruba ClearPass
OWASP API Security Top 10 - API World
Getting the most out of the Aruba Policy Enforcement Firewall
Alphorm.com Formation Microsoft Azure : Azure Active Directory 2021
Palo Alto Networks 28.5.2013
ClearPass Policy Model - An Introduction
Understanding Azure AD
Ad

Viewers also liked (20)

PDF
Designing for the all wireless office ash chowdappa-kelly griffin
PDF
3 air wave practical workshop_mike bruno_matt sidhu
PDF
2 top10 tips from aruba tac rizwan shaikh
PDF
1 voice and video over wi fi-balajee krishnamurthy
PDF
Rf troubleshooting advanced kelly griffin_peter lane
PDF
2012 ah vegas remote networking fundamentals
PDF
2012 ah vegas guest access fundamentals
DOCX
Mac authentication amigopod radius
PDF
Gigabit wifi 802.11 ac in depth_peter thornycroft
PDF
PDF
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
PDF
Security intermediate practical cryptography_certs_and 802.1_x_rich langston...
PDF
8 software defined networking and traffic engineering partha narasimhan_ash c...
PDF
Aruba networks webinar_wi-fi_without_interruption_sep20_2012
PDF
2012 ah emea advanced mobility design
PDF
Do d directives regarding wireless lan
PDF
2012 ah vegas top10 tips from aruba tac
PDF
Aruba instant the easy button for wireless gokul rajagopalan
PDF
2012 ah vegas unified access fundamentals
Designing for the all wireless office ash chowdappa-kelly griffin
3 air wave practical workshop_mike bruno_matt sidhu
2 top10 tips from aruba tac rizwan shaikh
1 voice and video over wi fi-balajee krishnamurthy
Rf troubleshooting advanced kelly griffin_peter lane
2012 ah vegas remote networking fundamentals
2012 ah vegas guest access fundamentals
Mac authentication amigopod radius
Gigabit wifi 802.11 ac in depth_peter thornycroft
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
Security intermediate practical cryptography_certs_and 802.1_x_rich langston...
8 software defined networking and traffic engineering partha narasimhan_ash c...
Aruba networks webinar_wi-fi_without_interruption_sep20_2012
2012 ah emea advanced mobility design
Do d directives regarding wireless lan
2012 ah vegas top10 tips from aruba tac
Aruba instant the easy button for wireless gokul rajagopalan
2012 ah vegas unified access fundamentals
Ad

Similar to Clear pass policy manager advanced_ashwath murthy (20)

PDF
Breakout - Airheads Macau 2013 - ClearPass Access Management Basics
PPTX
Access Management with Aruba ClearPass #AirheadsConf Italy
PPTX
Shanghai Breakout: Access Management with Aruba ClearPass
PPTX
Defining Advanced AAA Policies for Access Networks
PDF
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
PPTX
Breakout - Airheads Macau 2013 - BYOD, MDM, and MAM
PPTX
PDF
Clear pass access management basics zach jennings
PDF
Security advanced rich langston_jon green
PDF
Clear passbasics derinmellor
PDF
ClearPass Policy Manager 6.3 User Guide
PDF
ClearPass Policy Manager 6.3 User Guide
PPTX
Enabling AirPrint & AirPlay on Your Network
PPTX
Real-world 802.1X Deployment Challenges
PPTX
PPTX
Enabling the Virtual Enterprise
PPTX
ClearPass_Design Info.pptx
PPTX
Securing the LAN Best practices to secure the wired access network
PPTX
ClearPass_Customer_Presentation
Breakout - Airheads Macau 2013 - ClearPass Access Management Basics
Access Management with Aruba ClearPass #AirheadsConf Italy
Shanghai Breakout: Access Management with Aruba ClearPass
Defining Advanced AAA Policies for Access Networks
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Breakout - Airheads Macau 2013 - BYOD, MDM, and MAM
Clear pass access management basics zach jennings
Security advanced rich langston_jon green
Clear passbasics derinmellor
ClearPass Policy Manager 6.3 User Guide
ClearPass Policy Manager 6.3 User Guide
Enabling AirPrint & AirPlay on Your Network
Real-world 802.1X Deployment Challenges
Enabling the Virtual Enterprise
ClearPass_Design Info.pptx
Securing the LAN Best practices to secure the wired access network
ClearPass_Customer_Presentation

More from Aruba, a Hewlett Packard Enterprise company (20)

PPTX
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
PPTX
Airheads Tech Talks: Advanced Clustering in AOS 8.x
PPTX
EMEA Airheads_ Advance Aruba Central
PPTX
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
PPTX
EMEA Airheads- Switch stacking_ ArubaOS Switch
PPTX
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
PPTX
PPTX
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
PPTX
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
PPTX
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
PPTX
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
PPTX
EMEA Airheads- Manage Devices at Branch Office (BOC)
PPTX
EMEA Airheads - What does AirMatch do differently?v2
PPTX
Airheads Meetups: 8400 Presentation
PPTX
Airheads Meetups: Ekahau Presentation
PPTX
Airheads Meetups- High density WLAN
PPTX
Airheads Meetups- Avans Hogeschool goes Aruba
PPTX
EMEA Airheads - Configuring different APIs in Aruba 8.x
PPTX
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
PPTX
EMEA Airheads - Multi zone ap and centralized image upgrade
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Advanced Clustering in AOS 8.x
EMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads - What does AirMatch do differently?v2
Airheads Meetups: 8400 Presentation
Airheads Meetups: Ekahau Presentation
Airheads Meetups- High density WLAN
Airheads Meetups- Avans Hogeschool goes Aruba
EMEA Airheads - Configuring different APIs in Aruba 8.x
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
EMEA Airheads - Multi zone ap and centralized image upgrade

Recently uploaded (20)

PDF
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
PDF
20250805_A. Stotz All Weather Strategy - Performance review July 2025.pdf
PDF
Power and position in leadershipDOC-20250808-WA0011..pdf
PDF
Roadmap Map-digital Banking feature MB,IB,AB
PPTX
Probability Distribution, binomial distribution, poisson distribution
PDF
kom-180-proposal-for-a-directive-amending-directive-2014-45-eu-and-directive-...
PDF
IFRS Notes in your pocket for study all the time
PPTX
Lecture (1)-Introduction.pptx business communication
PDF
DOC-20250806-WA0002._20250806_112011_0000.pdf
PPT
340036916-American-Literature-Literary-Period-Overview.ppt
PDF
Nidhal Samdaie CV - International Business Consultant
DOCX
unit 2 cost accounting- Tender and Quotation & Reconciliation Statement
PPT
Chapter four Project-Preparation material
PPTX
ICG2025_ICG 6th steering committee 30-8-24.pptx
DOCX
Euro SEO Services 1st 3 General Updates.docx
PDF
Business model innovation report 2022.pdf
PPTX
AI-assistance in Knowledge Collection and Curation supporting Safe and Sustai...
PDF
Types of control:Qualitative vs Quantitative
PDF
MSPs in 10 Words - Created by US MSP Network
PDF
Elevate Cleaning Efficiency Using Tallfly Hair Remover Roller Factory Expertise
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
20250805_A. Stotz All Weather Strategy - Performance review July 2025.pdf
Power and position in leadershipDOC-20250808-WA0011..pdf
Roadmap Map-digital Banking feature MB,IB,AB
Probability Distribution, binomial distribution, poisson distribution
kom-180-proposal-for-a-directive-amending-directive-2014-45-eu-and-directive-...
IFRS Notes in your pocket for study all the time
Lecture (1)-Introduction.pptx business communication
DOC-20250806-WA0002._20250806_112011_0000.pdf
340036916-American-Literature-Literary-Period-Overview.ppt
Nidhal Samdaie CV - International Business Consultant
unit 2 cost accounting- Tender and Quotation & Reconciliation Statement
Chapter four Project-Preparation material
ICG2025_ICG 6th steering committee 30-8-24.pptx
Euro SEO Services 1st 3 General Updates.docx
Business model innovation report 2022.pdf
AI-assistance in Knowledge Collection and Curation supporting Safe and Sustai...
Types of control:Qualitative vs Quantitative
MSPs in 10 Words - Created by US MSP Network
Elevate Cleaning Efficiency Using Tallfly Hair Remover Roller Factory Expertise

Clear pass policy manager advanced_ashwath murthy

  • 1. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 1 #airheadsconf#airheadsconf ClearPass Policy Manager – Advanced Ashwath Murthy 03/15/2013
  • 2. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 2 #airheadsconf ClearPass – Policy Model Authorization – What and Why? Profile – How does it work? Clustering & Deployment Q & A Agenda
  • 3. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 3 #airheadsconf#airheadsconf3 ClearPass Policy Model
  • 4. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 4 #airheadsconf •  What constitutes the policy model? •  How does it work? •  What are the interactions between various components? •  How does the policy model affect configuration & deployment? ClearPass Policy Model
  • 5. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 5 #airheadsconf ClearPass Policy Model Policy Identity Health Device Conditions • Role • Department • Group •  AV, AS, FW • Registry Keys • Services… • Device type, status, health • Address, O/S • Corp. Owned • Time • Location • Day of Week
  • 6. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 6 #airheadsconf What’s the flow? Authenticate • Valid Authentication Authorize • Find Out What’s Allowed Associate Context • Device, Time, Location, Posture Enforce on NAS • Roles, ACLs, VLANs
  • 7. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 7 #airheadsconf What Are The Interactions? RADIUS Server – Authenticate Policy Server – Authorize Policy Server – Associate Context Policy Server – Decision Tree RADIUS Server – Enforce
  • 8. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 8 #airheadsconf Service Flow – 802.1X Layer 2 RADIUS Request Layer 2 Authentication Layer 2 Authorization Layer 2 Role Derivation Layer 2 RADIUS Enforcement Layer 3 Profile Layer 2 NAP Layer 3 OnGuard
  • 9. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 9 #airheadsconf •  Layer 2 Authentications are completed first –  Full Authorization –  Role Derivation –  NAP (if enabled) –  Layer 2 Enforcement •  Layer 3 : Profile next –  DHCP Request, DHCP Offer –  RFC 3576 – Change of Authorization •  Another Layer 2 authentication! –  No RFC 3576 message if “fingerprint” does not change •  Layer 3 : Collect Posture last (OnGuard) –  Posture over HTTPS –  RFC 3576 based on policy •  Another Layer 2 authentication! Service Flow – Implications
  • 10. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 10 #airheadsconf#airheadsconf10 Authorization – What and Why?
  • 11. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 11 #airheadsconf •  Authentication vs. Authorization •  Authorization & ClearPass •  Use Cases Authorization – What and Why?
  • 12. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 12 #airheadsconf Authorization & ClearPass •  “Authorization” Sources in ClearPass –  Where do I find them? –  How do I use them? –  How often does ClearPass talk to an authorization source? –  What happens in case something goes wrong?
  • 13. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 13 #airheadsconf •  An “Authentication Source” is an “Authorization Source” –  RADIUS Server vs. Policy Server Authorization Sources – Where?
  • 14. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 14 #airheadsconf Authorization Sources – How? Authentication Sources are automatic Authorization Sources Additional Authorization Sources enabled per Service No Authorization unless used in Roles!
  • 15. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 15 #airheadsconf Authorization Sources – How? Authorize with Active Directory Authorize with Profile Data Rule Algorithm : Evaluate All
  • 16. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 16 #airheadsconf •  Ok, great. But will ClearPass flood my AD with authorization requests? –  Authorization data is cached per user –  New request made to fetch data once the cache expires –  Cache timers can be tuned Authorization – How? Cache Timeout Default: 10 hours
  • 17. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 17 #airheadsconf •  Got it •  But I just made a bunch of changes on my AD. Should I need to wait 10 hours? –  Tune the cache timers –  “Clear Cache” button on the Authentication Source •  Wipes out cache for all users –  “Save” button on the Authentication Source •  Wipes out cache for all users –  Restart Policy Server •  BAD IDEA!!! Authorization – How?
  • 18. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 18 #airheadsconf •  If an Authentication/Authorization Source is not reachable –  Configure Backup Servers –  Configure Fail-Over Timeout Authorization – Uh-Oh! Fail-Over Timeout Backup Servers
  • 19. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 19 #airheadsconf Use Cases – Mergers & Acquisitions Active Directory Domain – avendasys.com Active Directory Domain – arubanetworks.com
  • 20. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 20 #airheadsconf Authentication & Authorization Sources for TLS Certificate Details used for Authorization Enable Authorization – Source specified in the Service Compare Certificate – Source specified in the Service Use Cases – Certificates & TLS
  • 21. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 21 #airheadsconf •  LDAP/SQL Interface to Asset Databases –  Key : MAC Address –  Authorization Attributes •  Ownership – Corporate vs. Personal •  Compliance Status – In/Out of compliance –  Identify corporate-owned non-Windows devices Use Cases – Asset Databases
  • 22. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 22 #airheadsconf#airheadsconf22 Profile – How does it work?
  • 23. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 23 #airheadsconf •  Profile & Network Data •  Automatic Profile “upgrades” •  Using Profile data in policy •  Configuring Profile –  DHCP? HTTP? SNMP? •  Use Cases Profile – How does it work?
  • 24. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 24 #airheadsconf •  What does ClearPass use to profile? –  MAC OUIs –  DHCP Request, DHCP Offer –  HTTP User-Agent –  MDM Fingerprints –  Device Interrogation –  SNMP/CDP/LLDP Data Profile & Network Data
  • 25. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 25 #airheadsconf Fingerprint Updates •  Subscribe to Fingerprint Updates –  Automatic reclassification –  Updated frequently •  Tell Aruba! –  Create policy exceptions –  Grab fingerprints from UI –  Send fingerprints to Aruba –  Crowd-sourced, community oriented
  • 26. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 26 #airheadsconf •  Automatic 3-level categorization –  Device Category, OS Family, Device Name •  Using raw profile data –  DHCP Data, HTTP User-Agent, SNMP Data •  Role Mapping –  What should I use? •  Enforcement –  How do I enforce? –  What are the benefits? Using Profile data in policy
  • 27. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 27 #airheadsconf •  DHCP Relay –  Where should I setup DHCP relays? •  Captive Portal Configuration –  Is there a knob for this? •  Reading SNMP Data –  CDP –  LLDP –  HR MIB –  SysDescr MIB Configuring Profile – Network Considerations
  • 28. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 28 #airheadsconf •  Policy – CEOs & iPads •  Policy – “Headless” Devices •  Visibility – Demystifying BYODs Use Cases
  • 29. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 29 #airheadsconf Use Cases – CEOs & iPads Assign Roles Enforce Access
  • 30. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 30 #airheadsconf Use Cases – Headless Devices Identify & Assign Roles To Headless Devices
  • 31. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 31 #airheadsconf Use Cases – Visibility
  • 32. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 32 #airheadsconf#airheadsconf32 Clustering & Deployment
  • 33. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 33 #airheadsconf •  Clustering Technology –  What’s replicated? What’s not? •  Deploying ClearPass Clusters –  Considerations •  Operations & Maintenance –  What happens when a ClearPass node is down? –  Events & Alerts –  Rescue & Recovery Clustering & Deployment
  • 34. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 34 #airheadsconf •  What’s replicated? –  All policy configuration elements –  All Audit data –  All identity store data •  Guest Accounts, Endpoints, Profile data –  Runtime Information •  Authorization status, Posture status, Roles •  Connectivity Information, NAS Details –  Database replication on port# 5432 over SSL –  Runtime replication on port# 443 over SSL Clustering Technology
  • 35. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 35 #airheadsconf •  What’s not replicated? –  Log files –  Authentication Records –  Accounting Records –  System Events –  System Monitor Data Clustering Technology
  • 36. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 36 #airheadsconf •  How do they connect? –  Requires IP connectivity (bi-directional) •  Port # 5432 (Database over SSL) •  Port# 80 (HTTP) •  Port #443 (HTTPS) •  Port #123 (NTP) •  How much data should we expect to see crossing the wire? –  Only elements in the configuration database –  First sync is a full database copy –  Subsequent sync – Delta changes propagated Clustering – Considerations
  • 37. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 37 #airheadsconf Clustering – Considerations PUBLISHER SUBSCRIBER 1 SUBSCRIBER 2 SUBSCRIBER 3 SUBSCRIBER 4 SUBSCRIBER 5 SUBSCRIBER 6 Hub & Spoke
  • 38. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 38 #airheadsconf Clustering – Considerations CPPM – Publisher DNS DHCP Identity Stores Main Data Center Mid-size Branch Regional Office DMZ CPPM Subscriber VM CP Guest CP Onboard CPPM Subscriber CPPM Subscriber •  Central / Distributed Admin Domains •  Redundancy/Load Balancing •  Cluster wide licenses
  • 39. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 39 #airheadsconf •  What happens when a node goes down? –  Operations •  If Deployed Right – Nothing •  RADIUS Backup settings on the NAS –  If the Publisher goes down •  No Database Writes Allowed!! •  Promote a Subscriber to a Publisher •  Resume configuration updates Operations & Maintenance
  • 40. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 40 #airheadsconf •  How long before ClearPass figures out something’s wrong? –  24 hours before it automatically “drops” a node from the cluster –  Cluster Synchronization Warnings •  1 event every hour x 24 hours = 24 events –  CPU/Memory Usage Warnings  Every 2 Minutes –  Server Certificate Warnings  Every 24 Hours –  Service Alerts  Immediate •  Email/SMS Alerts using Insight, Syslog & SNMP Events & Alerts
  • 41. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 41 #airheadsconf •  Rescue & Recovery –  Establish cluster connectivity •  Database sync will ensue. Watch for “Last Sync Time” –  Restore certificates •  Server Certificates are not installed as a part of the sync –  Restore log entries (If necessary) •  Caveat : High disk activity for an extended period of time –  Verify fail-back on the NAS •  NAS fail-back timers should kick in Operations & Maintenance
  • 42. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 42 #airheadsconf#airheadsconf42 Q & A
  • 43. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 43 #airheadsconf#airheadsconf Thank You
  • 44. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 44 #airheadsconf#airheadsconf44