QuestionQ33

Protect and Defend

Your company uses an HPE Aruba Networking AOS-10 architecture managed by HPE Aruba Networking Central. A ClearPass Policy Manager (CPPM) cluster supplies authentication. The company also has a Palo Alto firewall. You want to configure the HPE Aruba Networking infrastructure to quarantine clients for which the firewall sends Syslog Threat messages to CPPM.

Network infrastructure devices already have a “quarantine” role configured.

You checked the CPPM event dictionary and found an entry for Palo Alto Syslog Threats that includes:

  • Prefix: PANW-Threat
  • Attributes such as syslogtimestamp and logtype

What is a correct component of the configuration in ClearPass server settings?

  • A Insight server enabled
  • B CA that signed the firewall's certificate installed as trusted
  • C Syslog scanning configured
  • D CoA delay of 5 seconds or greater
Explanation

ClearPass Policy Manager’s Ingress Event Engine processes inbound third-party threat Syslog events and applies enforcement policies and actions. Syslog scanning must therefore be configured to ingest and parse Palo Alto Threat messages using the PANW-Threat event dictionary. The RADIUS Dynamic Authorization delay is configurable from 0 to 15 seconds and defaults to 2 seconds, so no minimum delay of 5 seconds applies.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!