ducthxnh
Intern
Cấu hình và cài đặt Clearpass Onguard Agent trên Windows thủ công
Ở đây sẽ sử dụng 1 mô hình mới setup tạo 2 vlan, 1 vlan 10 và 1 vlan 99
1. Cấu hình chi tiết trên Palo Alto Firewall
1.1 Cấu hình Security Policies đảm bảo nguyên tắc Zero Trust: mở đúng cổng dịch vụ cho từng vùng mạng.
Khai báo Custom Service (TCP 6658) - Tạo Custom Service cho OnGuard Health Check
Vào Object > Service > Add
1.2 Các thông tin cấu hình các cổng / vlan
Ở đây vlan 1 sẽ là của Clearpass, vlan 10 là của employee - những ai đăng nhập bằng tài khoản nhân viên local trên clearpass thì sẽ được vào vlan 10, vlan 99 là những guest của hệ thống, chưa đăng nhập tài khoản local
1.3 Cấu hình Policies
Cấu hình cho Clearpass, Employee và Guest có thể ra được outside. Employee và Guest sẽ tới Clearpass và bao gồm cổng service 6658. Chặn Guest tới Employee
1.4 Các cấu hình khác bao gồm
a) NAT để ra Internet
b) Tự động cấp dhcp vlan 10 và vlan 99
c) Cấu hình Static Route
2. Cấu hình trên Switch AOS-CX
2.1 Cấu hình Switch Trung tâm (ArubaCX-SW-Core)
configure terminal
! 1. Tạo các VLAN
vlan 1
name SERVER_MGMT
vlan 10
name EMPLOYEE
vlan 99
name QUARANTINE
exit
! 2. Cổng 1/1/1 nối lên Palo Alto (Trunk mang tất cả VLAN)
interface 1/1/1
no shutdown
no routing
vlan trunk native 1
vlan trunk allowed 1,10,99
exit
! 3. Cổng 1/1/2 nối xuống SW1 (Trunk)
interface 1/1/2
no shutdown
no routing
vlan trunk native 1
vlan trunk allowed 1,10,99
exit
! 4. Cổng 1/1/3 nối xuống SW2 (Trunk)
interface 1/1/3
no shutdown
no routing
vlan trunk native 1
vlan trunk allowed 1,10,99
exit
! 5. Cổng 1/1/4 nối ClearPass Data Interface (Access VLAN 1)
interface 1/1/4
no shutdown
no routing
vlan access 1
exit
! 6. Quản trị Switch Local
user admin group administrators password plaintext 123456
ssh server vrf default
write memory
2.2 Cấu hình Switch Truy cập 1 (ArubaCX-SW1 - Cổng nối Win A)
configure terminal
! 1. Khai báo VLAN
vlan 1,10,99
exit
! 2. Cổng Uplink nối lên Core
interface 1/1/1
no shutdown
no routing
vlan trunk native 1
vlan trunk allowed 1,10,99
exit
! 3. IP Quản trị SVI VLAN 1
interface vlan 1
ip address 192.168.1.21/24
no shutdown
exit
! 4. Khai báo RADIUS Server & CoA chuẩn AOS-CX
radius-server host 192.168.1.10 key plaintext ClearPass@123
radius dyn-authorization enable
radius dyn-authorization client 192.168.1.10 secret-key plaintext ClearPass@123
aaa group server radius CPPM_GROUP
server 192.168.1.10
exit
! 5. Bật 802.1X cấp Global
aaa authentication port-access dot1x authenticator
radius server-group CPPM_GROUP
enable
exit
! 6. Bật 802.1X cấp Cổng (Win A)
interface 1/1/2
no shutdown
no routing
vlan access 99
aaa authentication port-access dot1x authenticator
enable
exit
aaa authentication port-access client-limit 1
exit
! 7. Quản trị Switch
user admin group administrators password plaintext 123456
ssh server vrf default
write memory
2.3. Cấu hình Switch Truy cập 2 (ArubaCX-SW2 - Cổng nối Win B & Linux)
configure terminal
! 1. Khai báo VLAN
vlan 1,10,99
exit
! 2. Cổng Uplink nối lên Core
interface 1/1/1
no shutdown
no routing
vlan trunk native 1
vlan trunk allowed 1,10,99
exit
! 3. IP Quản trị SVI VLAN 1
interface vlan 1
ip address 192.168.1.22/24
no shutdown
exit
! 4. Khai báo RADIUS Server & CoA chuẩn AOS-CX
radius-server host 192.168.1.10 key plaintext ClearPass@123
radius dyn-authorization enable
radius dyn-authorization client 192.168.1.10 secret-key plaintext ClearPass@123
aaa group server radius CPPM_GROUP
server 192.168.1.10
exit
! 5. Bật 802.1X cấp Global
aaa authentication port-access dot1x authenticator
radius server-group CPPM_GROUP
enable
exit
! 6. Bật 802.1X cấp Cổng (Win B & Linux)
interface 1/1/2
no shutdown
no routing
vlan access 99
aaa authentication port-access dot1x authenticator
enable
exit
aaa authentication port-access client-limit 1
exit
interface 1/1/3
no shutdown
no routing
vlan access 99
aaa authentication port-access dot1x authenticator
enable
exit
aaa authentication port-access client-limit 1
exit
! 7. Quản trị Switch
user admin group administrators password plaintext 123456
ssh server vrf default
write memory
3. Cấu hình trên Aruba ClearPass Policy Manager
3.1 Điều chỉnh Cluster-Wide Parameters (Cái này để tránh khi bạn chưa đồng bộ thời gian cho cả 2 thiết bị clearpass và win tránh lỗi)
Administration > Server Manager > Server Configuration > Bấm Cluster-Wide Parameters.
Tab General: Chỉnh Policy result cache timeout = 1440 (phút).
3.2 Cấu hình Posture Policy (Windows_Posture_Policy)
Configuration > Posture > Posture Policies > Add:
Posture Agent: Web Agent (hỗ trợ OnGuard).
Host Operating System: WINDOWS.
Plugin: Chọn ClearPass Windows Universal System Health Validator.
Cấu hình Plugin: Bật kiểm tra Windows Defender Firewall phải ở trạng thái ON.
3.3 Cấu hình OnGuard Settings
Administration > Agents and Software Updates > OnGuard Settings:
- Tab Settings: Mục Agent Customization > Mode: Chọn Check health - no authentication.
- Bấm Save.
Đây là chính sách định nghĩa máy Windows phải đạt tiêu chí gì để được coi là "Healthy". Dùng Posture Agent kiểu Web Agent, plugin ClearPass Windows Universal System Health Validator (SHV). Có 2 rule: Pass hết SHV check → HEALTHY; Fail bất kỳ check nào → QUARANTINE.
3.4 Cấu hình Enforcement Policy (Employee_Dynamic_VLAN_Policy) — hành động gán VLAN
Tạo 2 Profile cho vlan 99 và vlan 10
Configuration > Enforcement > Profile:
Vlan 99
Vlan 10
Mỗi profile là 1 RADIUS Access-Accept kèm attribute Tunnel-Private-Group-Id = VLAN 10 hoặc 99. Đây là cơ chế Dynamic VLAN assignment chuẩn IETF (RFC 3580).
Enforcement Policies — logic quyết định
Employee_Dynamic_VLAN_Policy
Và OnGuard_CoA_Policy
Sau khi OnGuard đánh giá xong posture, chính sách này quyết định gửi CoA gì xuống switch (ở đây luôn Bounce Port để buộc thiết bị re-auth lại 802.1X và nhận VLAN mới).
3.5 Services
DOT1X_Wired_Authentication
OnGuard_Posture_Processing_Service
Service kiểu Web-based Authentication, nhận dữ liệu health-check do Agent gửi lên qua HTTPS. Posture Policy áp dụng: Windows_Posture_Policy. Enforcement Policy: OnGuard_CoA_Policy.
Kiểm tra
Vì đã cấu hình fw cho phép vlan 99 truy cập clearpass nên truy cập vào vào cổng data của clearpass để down onguard về, check đường dẫn
Vào Administration » Agents and Software Updates » OnGuard Settings
Vì đã cấu hình ip data và chỉ cho ra cổng data chứ không cho vlan 99 ra net nên sẽ đổi ip tương ứng,
Sửa lại tương ứng với ip của bạn nhé
Proceed sẽ tải file .exe về
Kết quả, trước khi cài check ip là thuộc vlan 99
Sau khi cài
Renew lại thì ip là vlan 10, tương tự check log
Có 1 cái webauth
Trước đó nó thuộc vlan 99
Sau khi cài clearpass onguard và check firewall hoạt động thì
Nó đã sang vlan 10 - giờ các bạn check tắt fw thì nó sẽ sang lại vlaan 99
Bài viết liên quan
Được quan tâm
Bài viết mới