Dell Powerconnect W-ClearPass Hardware Appliances W-ClearPass Policy Manager 6 - Page 61

ClearPass Policy Manager Profile, Device Profile, Collectors

Page 61 highlights

Chapter 6 ClearPass Policy Manager Profile Profile is a ClearPass Policy Manager module that automatically classifies endpoints using attributes obtained from software components called Collectors. It can be used to implement "Bring Your Own Device" (BYOD) flows, where access has to be controlled based on the type of the device and the identity of the user. While offering a more efficient and accurate way to differentiate access by endpoint type (laptop versus tablet), ClearPass Profile associates an endpoint with a specific user or location and secures access for devices like printers and IP cameras. Profile can be set up in a network with minimal amount of configuration. Device Profile A device profile is a hierarchical model consisting of 3 elements - DeviceCategory, DeviceFamily, and DeviceName derived by Profile from endpoint attributes. l DeviceCategory - This is the broadest classification of a device. It denotes the type of the device. Examples include Computer, Smartdevice, Printer, Access Point, etc. l DeviceFamily - This element classifies devices into a category; this is organized based on the type of OS or type of vendor. For example, Windows, Linux, and Mac OS X are some of the families when the category is Computer. Apple, Android are examples of DeviceFamily when category is SmartDevice. l DeviceName - Devices in a family are further organized based on more granular details such as version. For example, Windows 7 and Windows 2008 server are device names under the Windows family. This hierarchical model provides a structured view of all endpoints accessing the network. In addition to the these, Profile also collects and stores the following: l IP Address l Hostname l MAC Vendor l Timestamp when the device was first discovered l Timestamp when the device was last seen Collectors Collectors are network elements that provide data to profile endpoints. The following collectors send endpoint attributes to Profile. l DHCP l ClearPass Onboard Dell Networking W-ClearPass Policy Manager 6.0 | User Guide 61

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372

Dell Networking W-ClearPass Policy Manager 6.0 | User Guide
61
Chapter 6
ClearPass Policy Manager Profile
Profile is a ClearPass Policy Manager module that automatically classifies endpoints using attributes obtained from
software components called Collectors. It can be used to implement “Bring Your Own Device” (BYOD) flows, where
access has to be controlled based on the type of the device and the identity of the user. While offering a more
efficient and accurate way to differentiate access by endpoint type (laptop versus tablet), ClearPass Profile associates
an endpoint with a specific user or location and secures access for devices like printers and IP cameras. Profile can be
set up in a network with minimal amount of configuration.
Device Profile
A device profile is a hierarchical model consisting of 3 elements - DeviceCategory, DeviceFamily, and DeviceName
derived by Profile from endpoint attributes.
l
DeviceCategory - This is the broadest classification of a device. It denotes the type of the device. Examples
include Computer, Smartdevice, Printer, Access Point, etc.
l
DeviceFamily - This element classifies devices into a category; this is organized based on the type of OS or type
of vendor. For example, Windows, Linux, and Mac OS X are some of the families when the category is
Computer. Apple, Android are examples of DeviceFamily when category is SmartDevice.
l
DeviceName - Devices in a family are further organized based on more granular details such as version. For
example, Windows 7 and Windows 2008 server are device names under the Windows family.
This hierarchical model provides a structured view of all endpoints accessing the network.
In addition to the these, Profile also collects and stores the following:
l
IP Address
l
Hostname
l
MAC Vendor
l
Timestamp when the device was first discovered
l
Timestamp when the device was last seen
Collectors
Collectors are network elements that provide data to profile endpoints. The following collectors send endpoint
attributes to Profile.
l
DHCP
l
ClearPass Onboard