Configuring HPE ANW ClearPass v25.23 (ACP2)

Welcome to this week's class

Please be sure you have downloaded the learner guide and lab guide as per instructions you received from an email you would have received from HPE last week.  Check your email history, spam folder etc... for keyword "OnSecure" if you cannot find the email.

Tips on how to google our site for documentation

    • googling for AOS-Switch-related topics
      • site:hpe.com 16.10 -inurl:pdf -inurl:cx "dhcp-snooping"
    • googling for AOS-CX-related topics
      • site:arubanetworks.com -inurl:pdf inurl:AOS-CX inurl:10\.14 "dhcp-snooping"
    • search option notes:
      • site:x only searched that domain
      • -inurl:x don't report links with this text in the URL
      • inurl:x only report on links with text
        • (ideal for finding specific version documentation)

Helpful Links

    • about Aruba training and this course

    • where to find more information
    • where to find online documentation

    • ClearPass Policy Manager specific links

    • AOS-CX specific links

    • AP Datasheets

          • Remote APs
          • Indoor APs

        • GW Datasheets

                M01: Introduction

                Lab 1 - Testing Remote Lab Connectivity

                M02: Authentication, Authorization, & Accounting

                Lab 2: Configuring Authentication Sources

                    • 2.1: Explore CPPM Interface
                    • 2.2: Join CP to AD
                      • 2.3: Configure AD Authentication Source
                      • 2.4: Select Custom Attributes from AD
                      • 2.5: Test your AD Auth Source

                  M03: External Connectivity

                  Lab 3: Configuring External Devices

                      • 3.1: Configure Network Devices
                      • 3.2: Configure Device Attributes and Network Device Groups
                        • 3.3: Configure Email Server
                        • 3.4: Connecting ClearPass to MDM Server

                    M04: Endpoint Profiling

                    Lab 4: Endpoint Profiling

                        • 4.1: View Current Endpoints
                        • 4.2: Configure the controller for endpoint profiling
                          • 4.3: Configure profiling on ClearPass
                          • 4.4: Examine Endpoint Profile Data

                      Day 2 - Lecture Modules & Labs 

                      M05: Roles Enforcement Concepts

                      Lab 5: Roles and Enforcement

                          • 5.1: Plan your Enforcement
                          • 5.2: Create Local User Account
                            • 5.3: Create ClearPass Roles
                            • 5.4: Build Role Mapping Rules
                            • 5.5: Configure Enforcement Profiles
                            • 5.6: Configure Enforcement Policies

                        M06: Configuring Services

                        Lab 6: Configuring Services

                            • 6.1: Plan your services
                            • 6.2: Configure the Aruba Wireless 802.1x Service
                            • 6.3: Test a Failed Authentication Request
                            • 6.4: Testing the Aruba Wireless 802.1X Service

                        M07: Configuring Web Services

                        Lab 7: Web Services 

                            • 7.1: Upload File into Content Manager
                            • 7.2: Customize Built-in Skins
                            • 7.3: Customize Service Unavailable Page

                        Day 3 - Lecture Modules & Labs 

                        M08: Guest Access

                        Lab 8-A: Guest Access

                            • 8.1: Create Web Login Page
                            • 8.2: Create a Guest Account
                              • 8.3: Create Services for Guest in Policy Manager
                              • 8.4: Configure Aruba Controller for Guest
                              • 8.5: Test the Web Login page

                          Lab 8-B: Guest Authentication with MAC Caching

                              • 8.1: Create MAC Auth Service
                              • 8.2: Enable MAC Authentication on Controller
                                • 8.3: Testing

                            M09: Guest Access with Self-Registration

                            Lab 9: Guest Access with Self-Registration

                                • 9.1: Configure a Self-Registration portal
                                  • 9.1.6 (page 20[34]) common student mistake
                                    • be sure to find all 3 instances of
                                      • guest_register_confirm.php
                                    • and replace with
                                      • 'https://{IP of your ClearPass server}/guest/guest_register_confirm.php'
                                    • the way the lab guide is written, many students only change 2 of these, but not all three
                                • 9.2: Configure Aruba Controller for Self-Registration
                                  • 9.3: Testing Self-Registration

                              M10: Wired Authentication

                              Lab 10: Wired Authentication

                                  • 10.1: Configure the Service for Wired Authentication
                                  • 10.2: Configure the Switch Port for 802.1X
                                  • 10.3: Test the wired authentication port
                                  • 10.4: Return the Configuration to Normal

                              Day 4 - Lecture Modules & Labs 

                              M11: OnGuard Configuration

                              Lab 11: OnGuard Configuration

                                  • 11.1: Create a Posture Policy
                                  • 11.2: Create Enforcement Profiles
                                    • 11.3: Create Posture Token Based Enforcement Policy
                                    • 11.4: Create Service to Process Health Check
                                    • 11.5: Configure and Install OnGuard Persistent Agent
                                    • 11.6: Testing the OnGuard Persistent Agent

                                M12: OnGuard in Enforcement

                                Lab 12: OnGuard Enforcement

                                    • 12.1: Modify the Enforcement Policy
                                    • 12.2: Modify the Wireless Service
                                      • 12.3: Modify the Health Check Service
                                      • 12.4: Testing

                                  M13: Onboard Provisioning

                                  Lab 13: Onboard Configuration

                                      • 13.1: Configure Onboard as Root CA
                                      • 13.2: Configure Onboard Network Settings
                                        • 13.3: Configure Onboard Configuration Profile & Provisioning Settings
                                        • 15.4: Create Onboard Services
                                        • 15.5: Configure BYOD-Provision role on Controller
                                        • 15.6: Testing Onboard

                                    M14: Onboard Administration

                                    Lab 14: Onboard Administration

                                        • 14.1: Deny Access to Deleted User
                                        • 14.2: Test OCSP
                                          • 14.3: Deny Access to the Device

                                      Day 5 - Lecture Modules & Labs

                                      M15: Administrative Operations

                                      Lab 15: Administrative Operations

                                          • 15.1: Certificate Stores
                                          • 15.2: Licenses
                                          • 15.3: Backups and Logs

                                      M16: Administrative Access

                                      Lab 16: Administrative Operations

                                          • 16.1: Guest Operator Login
                                          • 16.2: Create new Guest Admin Account
                                          • 16.3: Test Guest Operator Account
                                          • 16.4: Policy Manager Admin Access for AD users
                                          • 16.5: Policy Manager Admin privileges
                                          • 16.6: TACACS+ Admin Access to Aruba Devices

                                      M17: Insight Reports

                                      Lab 17: Insight Reports

                                          • 17.1: Configuring Insight
                                          • 17.2: Explore the Insight Dashboard
                                          • 17.3: Creating Reports in Insight
                                          • 17.4: Alerts and Watchlist

                                      M18: Cluster (part of expert course)

                                        • cluster certificates FIELD ADVISORY CLUSTERING IN 6.8
                                          • The process of clustering CPPM requires 2 certificate validations
                                          1. HTTPS certificate validation
                                            • 6.8  mandates the validation of HTTPS certificate between cluster nodes
                                              • self signed certs will cause subscribers to fail with 
                                                • make subscriber failed, “GET failed, Will retry”
                                            • solution 1: recommended
                                              • CPPM nodes are signed by a Public CA.
                                              • A wildcard or a cert containing the FQDN for all the nodes in the cluster within the SAN signed by a known Public CA can be used
                                              • Ensure the entire chain including the Root and Intermediates of the Signing Certificate Authority (CA) are enabled in the Trust list of the Publisher.
                                                • To enable a trusted CA, navigate to Administration > Certificates > Trust List.
                                                • Enable the CA to be trusted for “Usage = Others”.
                                            • solution 2: not recommended (it ignores trust validation for the nodes joining the cluster)
                                              • Login to the CLI of the CPPM node to be added as a subscriber using the appadmin credentials.
                                                • Once logged in, issue the command as shown below: 
                                                • [appadmin@CPPM2]# cluster make-subscriber -i <Publisher IP> -V 
                                              • Expiration of HTTPS certificate does not affect the existing cluster.
                                              • This works on relaxing HTTPS certificate requirements, but not Database certificate requirements
                                          2. Database certificate validation
                                            • you can use self-signed DB cert on your publisher, it's SAN field will be DNS:x.x.x.x (ip address of self)
                                              • however, you must export that cert, then import that cert into the new cluster nodes trust list before it can join your publisher as a subscriber
                                                • see the end of lab 18 for instructions on how to:
                                                  • export the cert in p12 format
                                                  • use openssl.exe to convert the p12 to PEM format which can be imported into the new cluster nodes trust list
                                            • but, best practice is to use a public CA to create certs for each cluster node, be sure the SAN for each is set to DNS:x.x.x.x (ip address of node it is installed on)
                                              • it cannot use the SAN IP:x.x.x.x format
                                              • be sure to install your CA's public cert the cluster's root chain of trust
                                                • this means you no longer need to install your trust anchors public certs in your nodes before you have them join your cluster
                                        • Lab 18: Cluster
                                          • 18.1: Enabling Clustering
                                            • 18.1.20: (on page 490)
                                              • after completing step 18.1.20 you MUST go to page 513 and complete all steps from the paragraph titled "Certificate conversion process from .p12 to .pem", then return to page 490 and continue from step 21
                                          • 18.2: Monitoring Clustering
                                          • 18.3: Configuring High Availability
                                          • 18.4: Testing High Availability

                                      Appendix

                                      • Acronyms or Key terms
                                        • 2.5.29.19 - Basic Constraints: (X.509 Certificate Extension)
                                          • This extension indicates if the subject may act as a CA, with the certified public key being used to verify certificate signatures
                                          • This is required for Cluster DB Certificates as of CPPM >= 6.8
                                      • Icon Key
                                      • Lab Access Errata
                                        • if experiencing any problems with remote lab access (WebGate):
                                          • be sure your browser is in private (incognito) mode
                                          • restart your browser and clear your cache and cookies
                                          • do not try to login unless you are 100 percent sure the login page is fully loaded
                                          • during login to Central, did you select the SSO option?
                                          • if you need to restart your windows host
                                            • in cmd.com type "shutdown /r /t 0"

                                      Comments

                                      Popular posts from this blog

                                      Arubanetworks Webgate - Copy and Paste instructions

                                      RF Optimisation in dense Lab deployments 8.0.1