HPE HPE Aruba Networks Networking ClearPass Workshop - Wired #4 - Dynamic Access List (dACL)

  Рет қаралды 13,852

Airheads Broadcasting

Airheads Broadcasting

Күн бұрын

Пікірлер: 8
@NetmanDarrell
@NetmanDarrell 6 ай бұрын
Hey @hermanrobers - Great video - very helpful. Does this work in the same way on Aruba access points, or is there a different way? I have a MAC based list that certain (very restricted devices) are only allowed to certain destinations - is this possible via wireless too? Thanks in advance for pointing me in the right direction.
@hermanrobers
@hermanrobers 6 ай бұрын
On Aruba WLAN this works different, if you search for DUR (Downloadable User Role), you probably will find what you need. Here's a video on DUR for Aruba Instant: kzbin.info/www/bejne/fqi2eYOur5x1a9E . For controllers it's slightly different.
@NetmanDarrell
@NetmanDarrell 6 ай бұрын
@@hermanrobers Brilliant - Thank you. I actually just worked on a Role-Based Access, and assigned the role using Clearpass, using the 'If Aruba-User-Role equals then assign role ' then the role has access rules defined on the AP. I have yet to test it. I'll review your way too. At least your way I don't have to set up 'x' roles on all the APs, just do it through ClearPass. THANK YOU!
@Atomizer83
@Atomizer83 6 жыл бұрын
Hi, This need updating as it does not seem to work on newer ClearPass versions. Im on 6.7.9 and specifically the notion "permit in ip from any to 10.1.254.0/24" makes the switch mad. Tells me "idm: ACL error - invalid destination IP address." I've tried all other combinations that I can think of, without any luck (10.1.254.0 255.255.255.0 and 10.1.254.0 0.0.0.255). If you have insight, I would appreciate it.
@andrewmac8109
@andrewmac8109 7 жыл бұрын
Hi Herman What would a DACL look like for a port that had a IP-PHONE and a PC connected to that phone. Restrict the phone but allow authenticated user to corp net?
@hermanrobers
@hermanrobers 7 жыл бұрын
Andrew, good question. The thing is that authentication, both 802.1X or MAC is done on a per mac address basis. So you can put a very limited ACLs on the phone, but still allow full access for the laptop connected through that phone. On the Aruba switches, this is the default behavior and if you want you can put the port in 'port mode' where the first device on the switch will determine the authentication. Other types of switches might have different names and support for it, but with many enterprise switches you can configure it like this. Bottom line is that in most cases you don't have to bother as the switch will handle the two devices on one port as they were single devices on multiple ports.
@andrewmac8109
@andrewmac8109 7 жыл бұрын
Thanks Herman - Just tried it out. Works as advertised.
@phoonjzc
@phoonjzc 6 жыл бұрын
ok
UFC 287 : Перейра VS Адесанья 2
6:02
Setanta Sports UFC
Рет қаралды 486 М.
Как Ходили родители в ШКОЛУ!
0:49
Family Box
Рет қаралды 2,3 МЛН
요즘유행 찍는법
0:34
오마이비키 OMV
Рет қаралды 12 МЛН
Access Control Lists | Cisco CCNA 200-301
13:28
CertBros
Рет қаралды 127 М.
Aruba ClearPass
3:49
Advizex
Рет қаралды 31 М.
Mechanical slingshot rifle gun pheasant hunting,one shot catching.
0:48
Wild Craftsman
Рет қаралды 14 МЛН
преобразовал старый молоток
0:55
Стакановец
Рет қаралды 2,3 МЛН
Выхлоп за 70р, дёшево и сердито!
0:28
IGORIAN TODAY
Рет қаралды 3,8 МЛН
Вы тоже заметили ?
0:28
Расул Шамоев
Рет қаралды 5 МЛН
Правильный выбор сделал? #shorts
1:01
Angel4Skvad
Рет қаралды 1,2 МЛН