+ All Categories
Home > Documents > ClearPass Welcome Home! - Airheads...

ClearPass Welcome Home! - Airheads...

Date post: 27-Jun-2020
Category:
Upload: others
View: 11 times
Download: 0 times
Share this document with a friend
32
#ATM15ANZ | @ArubaANZ ClearPass Welcome Home! Carlos Gómez Gallego Nov 18, 2015
Transcript
Page 1: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

#ATM15ANZ | @ArubaANZ

ClearPass – Welcome Home! Carlos Gómez Gallego

Nov 18, 2015

Page 2: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.2#ATM15ANZ | @ArubaANZ

Agenda Slide

• 3 minute overview

• Beyond Authentication

• ClearPass Exchange

• Demo Time!

Page 3: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

ClearPass Overview

Page 4: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

4#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

The amigopod Garage…

Page 5: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

5#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

ClearPass Security Platform

@ArubaNetworks

NETWORK

EDGE

NETWORK

CORE

Silo’d

Approach

Profiler

EMM / MDM

NAC

TACACS

RADIUS

Guest/BYOD

NGFW & SIEM

Guest

Employee

Employee BYOD

IoT Devices

Contractor

Administrator

USERS

Centralizing Policy and Workflow Automation

AD/

LDAP

SQL

SSO/

MFA

PKI

IDENTITY

SOURCES

Page 6: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

6#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

Network Architecture

Access Methods Policy Definition Points

Wired User

Wireless User

Policy Enforcement Points

Wireless

Controller

Wired Switch

Identity StoresSIEM SQL

MDM

Remote User

NGFW

Remote AP

Managed Endpoints

Page 7: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

Beyond Authentication

Page 8: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

8#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

AAA Framework Overview

Authorization

Accounting

2. Enforces privileges or services that a user can perform.

1. Compares credentials versus those stored in a database.

3. Measures usage for authzcontrol, billing, analysis.

4. Usually uses RADIUS to perform authentication

Authentication

Page 9: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

9#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

Authentication alone doesn’t provide context

Corporate Tablet BYOD Tablet

Authentication EAP-TLS

SSID CORP-SECURE

Authentication EAP-TLS

SSID CORP-SECURE

Internet OnlyInternet

and Corporate Apps

Page 10: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

10#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

Device

Profiling

• Samsung SM-G900

• Android

• “Jons-Galaxy”

EMM/MDM

• Personal owned

• Registered

• OS up-to-date

• Hansen, Jon [Sales]

• MDM enabled = true

• In-compliance = true

Identity

Stores

Network Devices• Hansen, Jon [Sales]

• Title – COO

• Dept – Executive office

• City – London

• Location – Bldg 10

• Floor – 3

• Bandwidth – 10Mbps

Sources of Usable Context

Page 11: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

11#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

Device

Profiling

• Samsung SM-G900

• Android

• “Jons-Galaxy”

EMM/MDM

• Personal owned

• Registered

• OS up-to-date

• Hansen, Jon [Sales]

• MDM enabled = true

• In-compliance = true

Identity

Stores

Enforcement

Points

• Hansen, Jon [Sales]

• Title – COO

• Dept – Executive office

• City – London

• Location – Bldg 10

• Floor – 3

• Bandwidth – 10Mbps

Adaptive Trust Identity• Hansen, Jon [Sales]

• COO, Executive Office

• London

• Personal Owned

• Samsung SM-G900

• Android 4.4, Knox

• MDM enabled = true

• In-compliance = true

• At Bldg 10, floor 3

• 21:22GMT, 21/12/14

Sources of Usable Context

Page 12: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

12#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

ClearPass Policy Model – AuthN vs AuthZ

ClearPass Policy Manager

AD/LDAP

Guest

Insight

Endpoint

Onboard

Service Matching

SQL

MDM

HTTP

Authentication

Authorization

Role Mapping

Enforcement

Username = Bob

Mac Address = XYZ

SSID = Secure

Location = Building 1

Request = Radius

Response = Radius

- Accept

- Reject

- Attributes

Added Context:

MDM Enrolled = True

Device Type = iPad

Owner = Bob

Required Apps = True

Active Sessions = 2

AD Group = Exec

Corp Asset = True

Page 13: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

13#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

Sample Role MappingDevice

Context

Auth

Context

User

Context

Cert

ContextMDM

Context

Onboard

Context

Page 14: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

14#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

Role-based Access Control

AP is

Untrusted

Virtual AP 1

SSID: Corp

Virtual AP 2

SSID:

Guest

Aruba Mobility

Controller

Executiv

e

Employee

Partner

Contractor

Guest

Security Boundary

Centralized Crypto

Sessions

Flow / Application

Classification

Enterprise

Network

End-to-end crypto boundary

Per-user virtual connection

Roles versus

VLANS

Military-grade

security

Policy Enforcement

Firewall (PEF)

Page 15: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

ClearPass Exchange

Page 16: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

16#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

What is ClearPass Exchange?

ClearPass Exchange provides context-sharing and integration of ClearPass services with many third-party devices and applications. This enables the coordination of security, operational or HR workflows based on policies defined in ClearPass

Customers can build their own integrations or choose from a series of pre-integrated solutions from Aruba.

Page 17: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

17#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

RADIUS REQUEST

Service

Matching

Authentication

Authorization

Role Mapping

RADIUS RESPONSE

HTTP ENFORCEMENT

Security and Operations

SDN Controllers

Cloud Applications

RADIUS Accounting

SYSLOG LEF, CEEF

Target: Firewalls, Proxy, UBA, SIEM

ClearPass

Exchange

Enforcement Options

Role Based Access

Page 18: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

18#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

RADIUS REQUEST

Service

Matching

Authentication

Authorization

Role Mapping

RADIUS RESPONSE

HTTP

ENFORCEMENT

RADIUS Accounting

SYSLOG LEF, CEEF

Target: Firewalls, Proxy, UBA, SIEM

ClearPass

Exchange

Enforcement Options

Role Based Access

Page 19: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

19#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

Streamlined Access Control

Multivendor Networks

Enterprise AAA, CoA, TACACS+

Autonomous APs

VPN

WLAN Controllers

Access Switches

SELF-SERVICE

Employee Driven

Provisioning

Page 20: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

20#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

ClearPass Exchange Components

External ‘Context Servers’

– The server or application you are connecting to

– Requires URL and Authentication credentials

Context Server ‘Actions’

– The custom payload to send

– Content Types: HTTP, PLAIN, XML, JSON

– HTTP Methods: GET, PUT, POST

– Include any stored attributes e.g.. User name, device type, location, etc.

Enforcement Profile and Policy

– ClearPass policy configuration

– Sets condition for when to trigger Action

– Multiple actions to multiple servers supported

Page 21: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

21#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

Example: Share context with Firewall

User and

Device

FW policy enforcedContext SharedEmployee Access

• Network, Data Center and Internet Firewalls

• No agents/clients required

• Dynamic User, Device and Posture visibility

• Applies similarly to Proxy Servers, SDN Controllers, etc

• Thomas

• Mac OS 10.9.3

• Marketing

• 10.0.1.12

• Posture: Healthy

Page 22: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

22#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

Example: Help Desk tickets with Context

Page 23: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

23#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

Automate Security Policy

AUTOMATE SECURITY

Tickets, Notifications &

Enforcement

SIEM/Helpdesk

Mobile Device Management

Next Generation Firewalls

Endpoint Security

SELF-SERVICE

Employee Driven

Provisioning

Page 24: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

24#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

Inbound Device Context from IPS/EMM

Adaptive Network Access based on Threat level

1.User connects and downloads threat

2.NGFW/IPS generates event to

ClearPass

3.Or EMM generates security event to

ClearPass

4.ClearPass isolates client on

network; informs other

enforcement points, triggers

additional scans and notifies

helpdesk

4

Internet FW

LAN/WLAN

Page 25: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

25#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

5

Leverage SIEM to alert on Threats

Adaptive Network Access based on Threat level

1. User connects and downloads threat

2. NGFW/IPS intercepts file and identifies

threat type

3. NGFW/IPS generates event to SIEM system

4. SIEM system sends threat details to CPPM

5. ClearPass isolates client on network; informs

other enforcement points, triggers additional

scans and notifies helpdesk

SIEM System

4

Datacenter FW

Internet FW

Page 26: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

26#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

BYO Identity

Identity Stores

Public or Private Providers

Identity SSO and MFA

Office Collaboration

Social Networks

SELF-SERVICE

Uses Existing Identity

Payment Management

Page 27: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

27#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

Policy Based Multi Factor Authentication

LAN/WLAN

Policy Triggers

Location

Time Schedule

Behavior

Page 28: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

28#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

Orchestrating Multiple Actions

Radius Action to

force notification

page

Send user

SMS/Push

notification

Update Palo

Alto FirewallOpen Help

Desk Ticket

Sound

the

alarm!

Send

Email to

security

team

Page 29: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

29#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

Developer friendly REST API framework

• OAUth2 based client authorization

• Built in API Explorer

• Ability to run inline tests

Page 30: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

30#ATM15ANZ | @ ArubaANZ CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.

Transition Content

ClearPass Exchange Recipes

Recipe site and tech note available to help with your integrations:

– Site:• http://community.arubanetworks.com/t5/ClearPass-Exchange-

Recipes/tkbc-p/clearpass-recipes

– TechNotes:• http://support.arubanetworks.com/Documentation/tabid/77/DMXModul

e/512/Command/Core_Download/Default.aspx?EntryId=15508

– Not to be confused with Aruba Solution Exchange• http://ase.arubanetworks.com

Page 31: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services
Page 32: ClearPass Welcome Home! - Airheads Communitycommunity.arubanetworks.com/aruba/attachments/aruba...ClearPass Exchange provides context-sharing and integration of ClearPass services

THANK YOU

#ATM15ANZ | @ArubaANZ

THANK YOU


Recommended