23
CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Advanced ClearPass - Workshop Ashwath Murthy June 2014

Advanced ClearPass Workshop

Embed Size (px)

DESCRIPTION

Workshop on ClearPass from our Airheads Local events.

Citation preview

Page 1: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Advanced ClearPass - Workshop

Ashwath Murthy

June 2014

Page 2: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Agenda

• Discover Monitor Secure• Network Security with ClearPass• Deploying NAC with OnGuard – Wired & Wireless NAC

– NAC – Best Practices

• TACACS+ for Network Device Security• BYOD with Onboard• Monitoring & Troubleshooting

Page 3: Advanced ClearPass Workshop

Network Security with ClearPass

Page 4: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Discover Monitor Secure

• Discover– Discover via profiling• DHCP

• Non-DHCP

• Monitor– Enable policies in “Monitor” Mode

• Secure– Secure Wireless, Wired and VPNs

Page 5: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Network Security – Wired & Wireless

• Strong Security with 802.1X– Enterprise Users

– Need for strong, session-driven security

• Captive Portals for Guest Access– Transient users such as Guests, Contractors

– Limited network access zones

– Weaker security settings

• BYOD with unique credentials– Employee BYO Devices

– Non-IT assets

Page 6: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Network Security – Wired & Wireless

• Authenticate & Authorize– Certificates

– UserID/Password

– Tokens/OTP

Page 7: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Network Security – Wired

• Enable 802.1X on access ports• Allow fall-back to less secure modes of access– Limit network access

• Segregate responsibilities– Aruba Roles

– VLANs

– ACLs/dACLs

– Upstream enforcement with L3-L7 firewalls such as Palo Alto

Page 8: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Network Security – Wired

• But I have older switches that do not support 802.1X!

• Use SNMP to enforce port status– Set VLANs and Session-Timeout values

– “Bounce” a port

– Send LinkUp/LinkDown and MAC Notification Traps to ClearPass

Page 9: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Network Security – Wired

• How will ClearPass set VLANs using SNMP?– Using the standard If-MIB

• SNMP VLANs and MAC Authentication? What!?– Redirect the user to a captive portal after MAB

– Authenticate & Authorize with the captive portal

Page 10: Advanced ClearPass Workshop

Wireless Access Security

Page 11: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Wireless – Enterprise

• Enable 802.1X – WPA/WPA2 Enterprise– Session-based keys for secure connectivity

– Terminate EAP on ClearPass – infrastructure is EAP-agnostic

– Consistent user experience and security practice across deployments

Page 12: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Wireless – Guest

• Enable Guest Access/MAC Authentication– This can be combined with a WPA/WPA2 Passphrase

– Networks are inherently open unless secured!

– Strong access restrictions• Tunneled VLANs

• Stateful ACLs

• DPI/Application Monitoring

Page 13: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Wireless – BYOD

• What about BYO Devices?• BYO Devices on the enterprise network– Deliver certificates to BYO Devices using Onboard

– Segregate responsibilities by identifying BYO Devices

– Control device life cycle

• BYO Devices on the guest network– Devices use a segregated guest network

– Limited network access

– Challenges with device life cycle

Page 14: Advanced ClearPass Workshop

NAC is Back, Baby!!!

Page 15: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

NAC

• Agent Types – Persistent/Dissolvable• Posture Assessment – Windows, Mac, Linux– Agent Types

– Health Check Options

• Enforcement Options– Role-based

– Application-based

– To remediate, or not to remediate?

• Wired NAC vs. Wireless NAC• NAC for VPN• Best Practices, Thoughts

Page 16: Advanced ClearPass Workshop

TACACS+ for Network Devices

Page 17: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

TACACS+

• TACACS+ Authentication– Console, Shell, UI Login

• TACACS+ Authorization– Command Authorization

– Command Levels

• TACACS+ Accounting– Accounting & Audit Trails

– Authorization vs. Accounting

• Vendor Specifics– TACACS+ Dictionaries

Page 18: Advanced ClearPass Workshop

BYOD with Onboard

Page 19: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

BYOD with Onboard

• CA Settings– Stand-alone CA

– Intermediate CA

– ADCS

• Configuration Payloads– iOS & Mac OS X

– Microsoft Windows

– Android

• Provisioning Settings– TLS? PEAP-MSCHAPv2?

– Security Settings

– Certificate Renewal

Page 20: Advanced ClearPass Workshop

Monitoring & Troubleshooting

Page 21: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Monitoring & Troubleshooting

• Monitoring on ClearPass– Access Tracker• Alerts Tab

• Accounting Tab

• “Show Logs”

– Analysis & Trending• Drill Down

– Policy Simulation

– Authentication Simulation

– Insight

Page 22: Advanced ClearPass Workshop

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Monitoring & Troubleshooting

• External Monitoring– SIEM with Syslog/APIs

– SNMP

– SQL Access

Page 23: Advanced ClearPass Workshop

#AirheadsLocal