Skip to content

Commit 6a39c48

Browse files
authored
Merge pull request #187695 from shhazam-ms/Tutorial-Clearpass
Tutorial: ClearPass - Sensor Redesign
2 parents c51b2aa + 9ae149a commit 6a39c48

File tree

3 files changed

+17
-24
lines changed

3 files changed

+17
-24
lines changed
53.5 KB
Loading
7.13 KB
Loading

articles/defender-for-iot/organizations/tutorial-clearpass.md

Lines changed: 17 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: In this tutorial, you will learn how to integrate Microsoft Defende
44
author: ElazarK
55
ms.author: v-ekrieg
66
ms.topic: tutorial
7-
ms.date: 11/09/2021
7+
ms.date: 02/07/2022
88
ms.custom: template-tutorial
99
---
1010

@@ -129,14 +129,10 @@ To enable viewing the device inventory in ClearPass, you need to set up Defender
129129

130130
**To configure ClearPass sync on the Defender for IoT sensor**:
131131

132-
1. In the Defender for IoT sensor, select **System Settings** from the left side panel.
133-
134-
1. In the **System Settings** pane, select :::image type="content" source="media/tutorial-clearpass/clearpass-icon.png" alt-text="Screenshot of the ClearPass icon from the left side.":::.
132+
1. In the Defender for IoT sensor, select **System settings** > **Integrations** > **ClearPass**.
135133

136134
1. Set the following parameters:
137135

138-
:::image type="content" source="media/tutorial-clearpass/settings.png" alt-text="Screenshot of the fill out the required information in the System Settings pane.":::
139-
140136
- **Enable Sync:** Enable the sync between Defender for IoT and ClearPass
141137

142138
- **Sync Frequency:** Define the sync frequency in minutes. The default is 60 minutes. The minimum is 5 minutes.
@@ -159,39 +155,36 @@ To enable viewing the alerts discovered by Defender for IoT in Aruba, you need t
159155

160156
**To define a ClearPass forwarding rule on the Defender for IoT sensor**:
161157

162-
1. In the Defender for IoT sensor, select **Forwarding** from the left panel.
163-
164-
1. In the **Forwarding** pane, select **Create Forwarding Rule**.
165-
166-
:::image type="content" source="media/tutorial-clearpass/forwarding.png" alt-text="Screenshot of the Forwarding pane with all of its options.":::
158+
1. In the Defender for IoT sensor, select **Forwarding** and then select **Create new rule**.
167159

168-
1. Add the name, and the severity of the rule, and then from the **Action** drop-down list, select **Send to** > **ClearPass**.
160+
1. Define a rule name.
169161

170-
:::image type="content" source="media/tutorial-clearpass/rule.png" alt-text="Screenshot of the create a Forwarding Rule.":::
162+
1. Define the rule conditions.
171163

172-
1. In the **Actions** pane, set the following parameters:
164+
1. In the Actions section, select **ClearPass**.
173165

174-
:::image type="content" source="media/tutorial-clearpass/actions.png" alt-text="Select your actions from the Actions pane.":::
166+
:::image type="content" source="media/tutorial-clearpass/create-rule.png" alt-text="Screenshot of, create a Forwarding Rule window.":::
175167

176-
| Parameter | Description |
177-
|--|--|
178-
| **Host** | Type the ClearPass server IP address. |
179-
| **Port** | Type the port of the ClearPass on which the forwarding is done. |
180-
| **Configure** | Set-up the following options to allow viewing of Defender for IoT alerts in the ClearPass system: <br />- **Report illegal function codes:** Protocol violations - Illegal field value violating ICS protocol specification (potential exploit).<br />- **Report unauthorized PLC programming and firmware updates:** Unauthorized PLC changes.<br />- **Report unauthorized PLC stop:** PLC stop (downtime).<br />- **Report malware related alerts:** Industrial malware attempts, such as TRITON, NotPetya.<br />- **Report unauthorized scanning:** Unauthorized scanning (potential reconnaissance). |
168+
1. In the **Host** field, define the ClearPass server IP and port to send alert information.
169+
1. Define which alert information you want to forward.
170+
- **Report illegal function codes:** Protocol violations - Illegal field value violating ICS protocol specification (potential exploit).
171+
- **Report unauthorized PLC programming and firmware updates:** Unauthorized PLC changes.
172+
- **Report unauthorized PLC stop:** PLC stop (downtime).
173+
- **Report malware related alerts:** Industrial malware attempts, such as TRITON, NotPetya.
174+
- **Report unauthorized scanning:** Unauthorized scanning (potential reconnaissance)
175+
1. Select **Save**.
181176

182-
1. Select **Submit**.
183177

184178
## Monitor ClearPass and Defender for IoT communication
185179

186180
Once the sync has started, endpoint data is populated directly into the Policy Manager EndpointDb, you can view the last update time from the integration configuration screen.
187181

188-
**To review the Last Sync time to ClearPass**:
182+
**To review the last sync time to ClearPass**:
189183

190184
1. Sign in to the Defender for IoT sensor.
191185

192-
1. Select **System Settings** from the left side panel.
186+
1. Select **System settings** > **Integrations** > **ClearPass**.
193187

194-
1. Select **ClearPass**.
195188

196189
:::image type="content" source="media/tutorial-clearpass/last-sync.png" alt-text="Screenshot of the view the time and date of your last sync.":::
197190

0 commit comments

Comments
 (0)