INFOBLOX & ARUBA CLEARPASS INTEGRATION - No Network Insight (Discovery) Requirement
Hello,
These templates remove the requirement for a NIOS Network Insight (Discovery) appliance for the Aruba ClearPass integration with Infoblox. Using these templates, they will gather and sync to Aruba as much NIOS asset information as possible without the need for Network Insight.
Note that due to current API limitations and the lack of Network Insight, IPv6 assets and Discovery events are NOT supported with these templates. However, all other events supported in the original templates are supported in these.
All other functionality, requirements, deployment instructions and Extensible Attributes found in the original post remain the same. There you can also find an overview of the integration, deployment guide, demo video, EA requirements and the original templates that require Network Insight.
Answers
-
I'm having the same issues with this integration as with the other Discovery templates. The initial API to create a sessions gets passed fine, but the -Aruba ClearPass Security- doesn't trigger an API.
0 -
The asset update API itself works, just not the security (triggered by rpz) API
0 -
Check the logs. Likely there is an issue with "Aruba_Sync" EA.
It should be set to "true" (low level). In the deployemnt guide there is an error (it says "True")
0 -
Already seen that, it is set to "true" lower caps.
0 -
w/o logs it's hard to say what is going on.
0 -
-
Looks like you are trying to automate RPZ event with a lease. I'm not sure why but the script didn't check for a lease (Fixed and Host were requested). I need to ping Sophia to check the logic.
1 -
Hello,
We have updated the Security template to accommodate for security events that occur on IP addresses containing only lease objects. Simply redownload the Aruba_Security_No_NI.txt on this post for the updated version. Note that if there is no object on an IP, it will not sync to Aruba because it does not have a MAC.
0 -
Thanks for the update, but unfortunatly I'm still running in the same issue.
Client has obtained a lease, it is visible in IPAM, but still no luck.
0 -
Hey @peteremm,
Thanks for sending the debug log! I can see right away that your Aruba_Secure EA is empty in both the parent network and IP address of the lease. This EA must be set to 'true' for at least one of these objects for all security events.
I see you have Aruba_Sync set to true, but this is only for asset syncing. Aruba_Secure is for security event syncing.
0
Categories
- All Categories
- 5.2K Forums
- 4.7K Critical Network Services
- 470 Security
- Visibility and Insights
- Ideas Portal
- Webinars & Events
- 275 Resources
- 275 News & Announcements
- Knowledge Base
- Infoblox Documentation Portal
- Infoblox Blog
- Support Portal
- 8 Members Hub
- 4 Getting Started with Community
- 4 Community Support