QuestionQ45

Protect and Defend

You want to use HPE Aruba Networking ClearPass Device Insight tags as conditions in CPPM role-mapping or enforcement-policy rules.

Which guidelines should you follow?

  • A Create an HTTP authentication source to the HPE Aruba Networking Central API that queries for the tags. To use that source as the type for rule conditions, add it an authorization source for the service in question.
  • B Use the Application type for the rule conditions; no extra authorization source is required for services that use policies with these rules.
  • C Use the Endpoints Repository type for the rule conditions; Add Endpoints Repository as a secondary authentication source for services that use policies with these rules.
  • D Use the Endpoint type for the rule conditions; no extra authorization source is required for services that use policies with these rules.
Explanation

ClearPass Device Insight synchronizes tags to Policy Manager as endpoint attributes. Those tags are available anywhere endpoint attributes are exposed, including service, role-mapping, and enforcement-policy rule editors; they are evaluated using the Endpoint condition type without adding an extra authorization source.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!