Aruba ClearPass Workshop (2021) - Wireless Access #5 Endpoint Entity Updates

preview_player
Показать описание
In the comments of our previous video, where we combined User Authentication with the cached [Machine Authenticated] role, it was mentioned that this does not always works flawlessly, and a possible workaround is to use the Endpoint Database to mark devices as Domain Computers to be less dependent on the Computer Authentication.

While this is not the most secure way of doing this (hint: EAP-TEAP), I decided to include this video as by changing the Role Mapping and Enforcement, we pave the road to EAP-TEAP.

⏰Timestamps:
00:00 Intro
01:14 The Endpoint Repository / Database
01:40 Endpoint Attributes
02:10 Automatic Endpoint Attribute Updates
04:00 Check results and modify Role Mapping & Enforcement
06:45 Summary and considerations
Рекомендации по теме
Комментарии
Автор

Great Video, and also want to thank you for the username\UPN video authentication. On the eap-teap video that your working on. What CPPM version supports it and is eap-teap more secure than eap-peap? In eap-peap can see that EAP-MSCHAPv2 still used as authentication and you've said earlier in one of you videos that EAP-MSCHAPv2 is not very secure. Looking forward your next video.Thank you Herman

daniloruiz
Автор

Great videos. Explained each concept nicely. By any chance you have dumps for HPE6-A82 preparation?

niirraaj
Автор

Great job @Hermans, did you make a special group in de AD for the machines only? and if yes did the clearpass used the AD name of the Mac-address?

Laith.Alkhazragy
Автор

Hello Herman,
Im using Aruba 6.11, and I can't choose "Domain Machine" while using Endpoint Type, why ?

SagittariusA