Top Banner
Advanced ClearPass Workshop Ashwath Murthy March, 2014
25

Advanced Aruba ClearPass Workshop

Jul 19, 2015

Download

Documents

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Advanced Aruba ClearPass Workshop

Advanced ClearPass – Workshop

Ashwath Murthy

March, 2014

Page 2: Advanced Aruba ClearPass Workshop

CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved2 #AirheadsConf

Agenda

Discover Monitor Secure

Network Security with ClearPass

Deploying NAC with OnGuard

Wired & Wireless NAC

NAC – Best Practices

TACACS+ for Network Device Security

BYOD with Onboard

Monitoring & Troubleshooting

Page 3: Advanced Aruba ClearPass Workshop

3CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Network Security with ClearPass

Page 4: Advanced Aruba ClearPass Workshop

4CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Discover Monitor Secure

• Discover

– Discover via profiling

• DHCP

• Non-DHCP

• Monitor

– Enable policies in “Monitor” Mode

• Secure

– Secure Wireless, Wired and VPNs

Page 5: Advanced Aruba ClearPass Workshop

5CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Network Security – Wired & Wireless

• Strong Security with 802.1X

– Enterprise Users

– Need for strong, session-driven security

• Captive Portals for Guest Access

– Transient users such as Guests, Contractors

– Limited network access zones

– Weaker security settings

• BYOD with unique credentials

– Employee BYO Devices

– Non-IT assets

Page 6: Advanced Aruba ClearPass Workshop

6CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Network Security – Wired & Wireless

• Authenticate & Authorize

– Certificates

– UserID/Password

– Tokens/OTP

Page 7: Advanced Aruba ClearPass Workshop

7CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Network Security – Wired

• Enable 802.1X on access ports

• Allow fall-back to less secure modes of access

– Limit network access

• Segregate responsibilities

– Aruba Roles

– VLANs

– ACLs/dACLs

– Upstream enforcement with L3-L7 firewalls such as Palo Alto

Page 8: Advanced Aruba ClearPass Workshop

8CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Network Security – Wired

• But I have older switches that do not support

802.1X!

• Use SNMP to enforce port status

– Set VLANs and Session-Timeout values

– “Bounce” a port

– Send LinkUp/LinkDown and MAC Notification Traps to

ClearPass

Page 9: Advanced Aruba ClearPass Workshop

9CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Network Security – Wired

• How will ClearPass set VLANs using SNMP?

– Using the standard If-MIB

• SNMP VLANs and MAC Authentication? What!?

– Redirect the user to a captive portal after MAB

– Authenticate & Authorize with the captive portal

Page 10: Advanced Aruba ClearPass Workshop

10CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Wireless Access Security

Page 11: Advanced Aruba ClearPass Workshop

11CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Wireless – Enterprise

• Enable 802.1X – WPA/WPA2 Enterprise

– Session-based keys for secure connectivity

– Terminate EAP on ClearPass – infrastructure is EAP-

agnostic

– Consistent user experience and security practice across

deployments

Page 12: Advanced Aruba ClearPass Workshop

12CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Wireless – Guest

• Enable Guest Access/MAC Authentication

– This can be combined with a WPA/WPA2 Passphrase

– Networks are inherently open unless secured!

– Strong access restrictions

• Tunneled VLANs

• Stateful ACLs

• DPI/Application Monitoring

Page 13: Advanced Aruba ClearPass Workshop

13CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Wireless – BYOD

• What about BYO Devices?

• BYO Devices on the enterprise network

– Deliver certificates to BYO Devices using Onboard

– Segregate responsibilities by identifying BYO Devices

– Control device life cycle

• BYO Devices on the guest network

– Devices use a segregated guest network

– Limited network access

– Challenges with device life cycle

Page 14: Advanced Aruba ClearPass Workshop

14CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

NAC is Back, Baby!!!

Page 15: Advanced Aruba ClearPass Workshop

15CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

NAC

• Agent Types – Persistent/Dissolvable

• Posture Assessment – Windows, Mac, Linux

– Agent Types

– Health Check Options

• Enforcement Options

– Role-based

– Application-based

– To remediate, or not to remediate?

• Wired NAC vs. Wireless NAC

• NAC for VPN

• Best Practices, Thoughts

Page 16: Advanced Aruba ClearPass Workshop

16CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

TACACS+ for Network Devices

Page 17: Advanced Aruba ClearPass Workshop

17CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

TACACS+

• TACACS+ Authentication

– Console, Shell, UI Login

• TACACS+ Authorization

– Command Authorization

– Command Levels

• TACACS+ Accounting

– Accounting & Audit Trails

– Authorization vs. Accounting

• Vendor Specifics

– TACACS+ Dictionaries

Page 18: Advanced Aruba ClearPass Workshop

18CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

BYOD with Onboard

Page 19: Advanced Aruba ClearPass Workshop

19CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

BYOD with Onboard

• CA Settings

– Stand-alone CA

– Intermediate CA

– ADCS

• Configuration Payloads

– iOS & Mac OS X

– Microsoft Windows

– Android

• Provisioning Settings

– TLS? PEAP-MSCHAPv2?

– Security Settings

– Certificate Renewal

Page 20: Advanced Aruba ClearPass Workshop

20CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Monitoring & Troubleshooting

Page 21: Advanced Aruba ClearPass Workshop

21CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Monitoring & Troubleshooting

• Monitoring on ClearPass

– Access Tracker

• Alerts Tab

• Accounting Tab

• “Show Logs”

– Analysis & Trending

• Drill Down

– Policy Simulation

– Authentication Simulation

– Insight

Page 22: Advanced Aruba ClearPass Workshop

22CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Monitoring & Troubleshooting

• External Monitoring

– SIEM with Syslog/APIs

– SNMP

– SQL Access

Page 23: Advanced Aruba ClearPass Workshop

23CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved#AirheadsConf

Q & A

Page 24: Advanced Aruba ClearPass Workshop

24CONFIDENTIAL

© Copyright 2014. Aruba Networks, Inc.

All rights reserved

Thank You

#AirheadsConf

Page 25: Advanced Aruba ClearPass Workshop

25