You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/tutorial-clearpass.md
+17-24Lines changed: 17 additions & 24 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ description: In this tutorial, you will learn how to integrate Microsoft Defende
4
4
author: ElazarK
5
5
ms.author: v-ekrieg
6
6
ms.topic: tutorial
7
-
ms.date: 11/09/2021
7
+
ms.date: 02/07/2022
8
8
ms.custom: template-tutorial
9
9
---
10
10
@@ -129,14 +129,10 @@ To enable viewing the device inventory in ClearPass, you need to set up Defender
129
129
130
130
**To configure ClearPass sync on the Defender for IoT sensor**:
131
131
132
-
1. In the Defender for IoT sensor, select **System Settings** from the left side panel.
133
-
134
-
1. In the **System Settings** pane, select :::image type="content" source="media/tutorial-clearpass/clearpass-icon.png" alt-text="Screenshot of the ClearPass icon from the left side.":::.
132
+
1. In the Defender for IoT sensor, select **System settings** > **Integrations** > **ClearPass**.
135
133
136
134
1. Set the following parameters:
137
135
138
-
:::image type="content" source="media/tutorial-clearpass/settings.png" alt-text="Screenshot of the fill out the required information in the System Settings pane.":::
139
-
140
136
-**Enable Sync:** Enable the sync between Defender for IoT and ClearPass
141
137
142
138
-**Sync Frequency:** Define the sync frequency in minutes. The default is 60 minutes. The minimum is 5 minutes.
@@ -159,39 +155,36 @@ To enable viewing the alerts discovered by Defender for IoT in Aruba, you need t
159
155
160
156
**To define a ClearPass forwarding rule on the Defender for IoT sensor**:
161
157
162
-
1. In the Defender for IoT sensor, select **Forwarding** from the left panel.
163
-
164
-
1. In the **Forwarding** pane, select **Create Forwarding Rule**.
165
-
166
-
:::image type="content" source="media/tutorial-clearpass/forwarding.png" alt-text="Screenshot of the Forwarding pane with all of its options.":::
158
+
1. In the Defender for IoT sensor, select **Forwarding** and then select **Create new rule**.
167
159
168
-
1.Add the name, and the severity of the rule, and then from the **Action** drop-down list, select **Send to** > **ClearPass**.
160
+
1.Define a rule name.
169
161
170
-
:::image type="content" source="media/tutorial-clearpass/rule.png" alt-text="Screenshot of the create a Forwarding Rule.":::
162
+
1. Define the rule conditions.
171
163
172
-
1. In the **Actions** pane, set the following parameters:
164
+
1. In the Actions section, select **ClearPass**.
173
165
174
-
:::image type="content" source="media/tutorial-clearpass/actions.png" alt-text="Select your actions from the Actions pane.":::
166
+
:::image type="content" source="media/tutorial-clearpass/create-rule.png" alt-text="Screenshot of, create a Forwarding Rule window.":::
175
167
176
-
| Parameter | Description |
177
-
|--|--|
178
-
|**Host**| Type the ClearPass server IP address. |
179
-
|**Port**| Type the port of the ClearPass on which the forwarding is done. |
180
-
|**Configure**| Set-up the following options to allow viewing of Defender for IoT alerts in the ClearPass system: <br />- **Report illegal function codes:** Protocol violations - Illegal field value violating ICS protocol specification (potential exploit).<br />- **Report unauthorized PLC programming and firmware updates:** Unauthorized PLC changes.<br />- **Report unauthorized PLC stop:** PLC stop (downtime).<br />- **Report malware related alerts:** Industrial malware attempts, such as TRITON, NotPetya.<br />- **Report unauthorized scanning:** Unauthorized scanning (potential reconnaissance). |
168
+
1. In the **Host** field, define the ClearPass server IP and port to send alert information.
169
+
1. Define which alert information you want to forward.
170
+
-**Report illegal function codes:** Protocol violations - Illegal field value violating ICS protocol specification (potential exploit).
171
+
-**Report unauthorized PLC programming and firmware updates:** Unauthorized PLC changes.
## Monitor ClearPass and Defender for IoT communication
185
179
186
180
Once the sync has started, endpoint data is populated directly into the Policy Manager EndpointDb, you can view the last update time from the integration configuration screen.
187
181
188
-
**To review the Last Sync time to ClearPass**:
182
+
**To review the last sync time to ClearPass**:
189
183
190
184
1. Sign in to the Defender for IoT sensor.
191
185
192
-
1. Select **System Settings**from the left side panel.
0 commit comments