Top Banner
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Advanced ClearPass - Workshop Ashwath Murthy June 2014
23

Advanced ClearPass Workshop

Nov 29, 2014

Download

Technology

Workshop on ClearPass from our Airheads Local events.
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Advanced ClearPass - Workshop

Ashwath Murthy

June 2014

Page 2: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Agenda

• Discover Monitor Secure• Network Security with ClearPass• Deploying NAC with OnGuard – Wired & Wireless NAC

– NAC – Best Practices

• TACACS+ for Network Device Security• BYOD with Onboard• Monitoring & Troubleshooting

Page 3: Advanced ClearPass Workshop

Network Security with ClearPass

Page 4: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Discover Monitor Secure

• Discover– Discover via profiling• DHCP

• Non-DHCP

• Monitor– Enable policies in “Monitor” Mode

• Secure– Secure Wireless, Wired and VPNs

Page 5: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Network Security – Wired & Wireless

• Strong Security with 802.1X– Enterprise Users

– Need for strong, session-driven security

• Captive Portals for Guest Access– Transient users such as Guests, Contractors

– Limited network access zones

– Weaker security settings

• BYOD with unique credentials– Employee BYO Devices

– Non-IT assets

Page 6: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Network Security – Wired & Wireless

• Authenticate & Authorize– Certificates

– UserID/Password

– Tokens/OTP

Page 7: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Network Security – Wired

• Enable 802.1X on access ports• Allow fall-back to less secure modes of access– Limit network access

• Segregate responsibilities– Aruba Roles

– VLANs

– ACLs/dACLs

– Upstream enforcement with L3-L7 firewalls such as Palo Alto

Page 8: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Network Security – Wired

• But I have older switches that do not support 802.1X!

• Use SNMP to enforce port status– Set VLANs and Session-Timeout values

– “Bounce” a port

– Send LinkUp/LinkDown and MAC Notification Traps to ClearPass

Page 9: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Network Security – Wired

• How will ClearPass set VLANs using SNMP?– Using the standard If-MIB

• SNMP VLANs and MAC Authentication? What!?– Redirect the user to a captive portal after MAB

– Authenticate & Authorize with the captive portal

Page 10: Advanced ClearPass Workshop

Wireless Access Security

Page 11: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Wireless – Enterprise

• Enable 802.1X – WPA/WPA2 Enterprise– Session-based keys for secure connectivity

– Terminate EAP on ClearPass – infrastructure is EAP-agnostic

– Consistent user experience and security practice across deployments

Page 12: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Wireless – Guest

• Enable Guest Access/MAC Authentication– This can be combined with a WPA/WPA2 Passphrase

– Networks are inherently open unless secured!

– Strong access restrictions• Tunneled VLANs

• Stateful ACLs

• DPI/Application Monitoring

Page 13: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Wireless – BYOD

• What about BYO Devices?• BYO Devices on the enterprise network– Deliver certificates to BYO Devices using Onboard

– Segregate responsibilities by identifying BYO Devices

– Control device life cycle

• BYO Devices on the guest network– Devices use a segregated guest network

– Limited network access

– Challenges with device life cycle

Page 14: Advanced ClearPass Workshop

NAC is Back, Baby!!!

Page 15: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

NAC

• Agent Types – Persistent/Dissolvable• Posture Assessment – Windows, Mac, Linux– Agent Types

– Health Check Options

• Enforcement Options– Role-based

– Application-based

– To remediate, or not to remediate?

• Wired NAC vs. Wireless NAC• NAC for VPN• Best Practices, Thoughts

Page 16: Advanced ClearPass Workshop

TACACS+ for Network Devices

Page 17: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

TACACS+

• TACACS+ Authentication– Console, Shell, UI Login

• TACACS+ Authorization– Command Authorization

– Command Levels

• TACACS+ Accounting– Accounting & Audit Trails

– Authorization vs. Accounting

• Vendor Specifics– TACACS+ Dictionaries

Page 18: Advanced ClearPass Workshop

BYOD with Onboard

Page 19: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

BYOD with Onboard

• CA Settings– Stand-alone CA

– Intermediate CA

– ADCS

• Configuration Payloads– iOS & Mac OS X

– Microsoft Windows

– Android

• Provisioning Settings– TLS? PEAP-MSCHAPv2?

– Security Settings

– Certificate Renewal

Page 20: Advanced ClearPass Workshop

Monitoring & Troubleshooting

Page 21: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Monitoring & Troubleshooting

• Monitoring on ClearPass– Access Tracker• Alerts Tab

• Accounting Tab

• “Show Logs”

– Analysis & Trending• Drill Down

– Policy Simulation

– Authentication Simulation

– Insight

Page 22: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Monitoring & Troubleshooting

• External Monitoring– SIEM with Syslog/APIs

– SNMP

– SQL Access

Page 23: Advanced ClearPass Workshop

#AirheadsLocal