ClearPass, developed by Aruba Networks, is a powerful network access control solution that provides secure network access for corporate and guest users. Here are ten best practices for optimizing ClearPass, particularly focusing on authentication.
## 1. Deploy ClearPass Clusters for Redundancy and Scalability
Deploy ClearPass clusters to provide better redundancy and scale out services. A ClearPass cluster consists of a Publisher and multiple Subscribers. The Publisher acts as the central point for configuration and maintains a central database to which Subscribers synchronize. In a production cluster, the Publisher is typically dedicated to managing and controlling the cluster while Subscribers respond to service requests and apply policies.
## 2. Use Certificates Signed by a Well-Known Public CA
To join the cluster, Subscribers must trust the HTTPS certificate on the Publisher. The best way to meet this requirement is to obtain a certificate signed by a well-known public CA on the Publisher. Then check that the Subscribers trust the complete chain for that certificate, including the root CA and one or more intermediate CAs.
## 3. Implement Certificate-Based Authentication
ClearPass Policy Manager (CPPM) supports multiple authentication methods, including certificate authentication. CPPM allows network device admins to define custom policies based on a user’s identity or device type. It also enables them to define policies based on context, such as a user’s location or the time of day.
## 4. Use ClearPass Onboard for Device Provisioning
ClearPass Onboard simplifies the process of provisioning devices with the settings and certificates required for a secure authentication. Onboard provides a self-service app that enables users to provision their own devices, rather than making this another task for IT.
## 5. Evaluate Endpoint Posture with ClearPass OnGuard
ClearPass OnGuard scans endpoints to determine their security posture. For example, it can verify firewall settings and ensure that a device’s patches are up-to-date. OnGuard communicates information about an endpoint’s security posture to CPPM. CPPM can then use that information to affect its access control decisions, deciding, for example, whether to quarantine the device.
## 6. Implement Role-Based Access Control
CPPM delivers role- and context-based access control based on highly flexible policies. The Aruba Unified Infrastructure receives the instructions from CPPM and enforces them with a powerful firewall.
## 7. Integrate with Unified Endpoint Management (UEM) Tools
CPPM can integrate with unified endpoint management (UEM) tools to gather context. With this data, CPPM can determine if a device’s OS is up-to-date or if the device is overall in-compliance. If the OS is not up-to-date or the device is not in-compliance, the Aruba network can react accordingly to protect the network from this vulnerability.
## 8. Use Identity Stores for User-Centric Context
CPPM uses identity stores to obtain more user-centric context. For example, the name, title, department, and location of an employee will be available through sources like Active Directory, which allows CPPM to precisely limit users’ access based on their actual needs.
## 9. Implement Continuous Monitoring and Enforcement
Aruba infrastructure conducts continuous monitoring on all connected endpoints to ensure that they are behaving appropriately. Built-in functionality such as intrusion detection, deep packet inspection (DPI), and web-traffic filtering based on site reputation make this possible.
## 10. Respond to Threats Based on Monitoring Results
Based on monitoring results, CPPM can make new decisions to respond to threats, and the Unified Infrastructure can enforce those decisions and mitigate threats.
By following these best practices, you can optimize ClearPass for secure and efficient authentication, ensuring a robust and secure network environment.
Related Articles
How Does Cerrtificate-based authentication work (802.1x TLS)
Explore the intricacies of 802.1X authentication, a cornerstone of secure network access, and understand how it integrates with Cisco switches and ClearPass as the RADIUS server.Lionel Medina is a seasoned expert in enterprise wireless design with over two decades of...
Post 7: Creating Your First SSID – Building the Wireless Network (Week 7)
Purpose Guide readers through SSID creation with security, VLAN, and RF settings, resulting in a live, joinable wireless network. Content Outline What is an SSID? SSID = Service Set Identifier (the Wi-Fi network name users see) Each SSID represents a wireless network...
Post 7: Creating Your First SSID – Building the Wireless Network (Week 7)
Purpose Guide readers through SSID creation with security, VLAN, and RF settings, resulting in a live, joinable wireless network. Content Outline What is an SSID? SSID = Service Set Identifier (the Wi-Fi network name users see) Each SSID represents a wireless network...

0 Comments