ducthxnh
Intern
Cấu hình Enforcement Profile và Enforcement Policy
I. Enforcement Logic Cơ chế Enforcement là mắt xích quyết định quyền truy cập mạng của Endpoint dựa trên hai luồng dịch vụ song song
- Luồng RADIUS 802.1X (DOT1X_Wired_Authentication): Switch gửi yêu cầu xác thực người dùng và tra cứu Posture Cache từ cơ sở dữ liệu [Endpoints Repository]. ClearPass đánh giá Role và Posture Token để trả về RADIUS Attribute Tunnel-Private-Group-Id tương ứng (VLAN 10 nếu Healthy, VLAN 99 nếu vi phạm hoặc chưa xác định).
- Luồng WebAuth OnGuard (OnGuard_Posture_Processing_Service): OnGuard Agent quét và gửi kết quả kiểm tra Endpoint về cổng TCP 6658. ClearPass cập nhật trạng thái Posture vào Cache, đồng thời kích hoạt Enforcement Profile gửi bản tin RADIUS Dynamic Authorization (CoA Bounce Port) xuống switch AOS-CX để ngắt link tạm thời, ép máy trạm re-auth và nhận VLAN mới.
Hệ thống cần 3 Enforcement Profile cốt lõi: 2 Profile gán VLAN qua RADIUS và 1 Profile điều khiển hạ tầng mạng qua CoA.
1. Profile cấp quyền VLAN 10 (VLAN10_Employee_Profile)
Configuration > Enforcement > Profiles > Add.
Template: VLAN Enforcement.
Profile Name: VLAN10_Employee_Profile
Tab Attributes:
2. Profile cách ly VLAN 99 (VLAN99_Quarantine_Profile)
Vẫn ở đó bấm add
Template: VLAN Enforcement.
Profile Name: VLAN99_Quarantine_Profile
Tab Attributes:
3. Profile có sẵn [AOS-CX - Bounce Switch Port]
Khi kích hoạt, ClearPass gửi bản tin CoA-Request chứa Vendor-Specific Attribute (VSA) Aruba-Port-Bounce-Host tới Switch AOS-CX qua cổng UDP 3799 để thực hiện link-flap.
III. Cấu hình Enforcement Policies
xây dựng 2 Policy độc lập áp dụng cho 2 dịch vụ tương ứng.
1. Policy gán quyền mạng 802.1X (Employee_Dynamic_VLAN_Policy)
Vào Configuration > Enforcement > Policies > Add.
Tab Enforcement
Tab Rules
Rule 1: Endpoint xác thực người dùng thành công và thỏa mãn toàn bộ tiêu chí Posture > cấp VLAN 10.
Rule 2: Người dùng hợp lệ nhưng máy vi phạm chính sách bảo mật (tắt FW, chạy P2P, thiếu Sophos) > giữ tại VLAN 99.
Rule 3: Endpoint mới kết nối, chưa được OnGuard quét trạng thái > đẩy tạm vào VLAN 99 chờ đánh giá.
2. Policy điều khiển phiên OnGuard WebAuth (OnGuard_CoA_Policy)
Tab Enforcement:
Name: OnGuard_CoA_Policy
Enforcement Type: WEBAUTH (Generic HTTP Web-Based Authentication)
Default Profile: [AOS-CX - Bounce Switch Port]
Tab Rules:
Rule 1: Endpoint sau khi quét đạt chuẩn hoặc đã tự khắc phục (Remediation) > Bounce port để Switch gán lại VLAN 10.
Rule 2: Endpoint phát hiện vi phạm mới > Bounce port để Switch lập tức tước quyền và hạ xuống VLAN 99.
IV. Gán Policy vào Services & Kích hoạt Posture Cache
Đảm bảo hai Service sau đã liên kết đúng Enforcement Policy vừa tạo:
1. Dịch vụ 802.1X (DOT1X_Wired_Authentication)
Configuration > Services > chọn DOT1X_Wired_Authentication
Tab Service: Tích chọn Authorization và Profile Endpoints.
Tab Authentication
Tab Authorization: Thêm [Endpoints Repository] vào danh sách Additional sources.
Tab Enforcement
2. Dịch vụ OnGuard WebAuth (OnGuard_Posture_Processing_Service):
Configuration > Services > chọn OnGuard_Posture_Processing_Service
Tab Service
Tab Authentication
Tab Posture: Gán Windows_Posture_Policy
Tab enforcement
Kiểm thử
Sau khi save thì máy win bên SW2 từ vlan 10 sẽ thành vlan99
Còn máy win từ sw1 đã có thì sẽ là vlan 10
Kiểm tra ở Access Tracker
Máy win 2 nằm vlan 99
Máy win 1
Đính kèm
Bài viết liên quan
Được quan tâm
Bài viết mới