Dell Powerconnect W-ClearPass Virtual Appliances W-ClearPass Guest 6.0 Deploym - Page 248

Creating a New Operator, External Operator Authentication

Page 248 highlights

Creating a New Operator To create a new operator or administrator for ClearPass Guest or AirGroup, some steps are performed in ClearPass Policy Manager (CPPM), and some steps are performed in ClearPass Guest, as described below: 1. Create an operator profile in ClearPass Guest, or use an existing one. See "Operator Profiles " on page 242. To create AirGroup users, choose either the AirGroup Administrator or AirGroup Operator profile, as appropriate. These profiles are automatically included in ClearPass Guest when the AirGroup Services plugin is installed. 2. Create a CPPM role for the operator: In ClearPass Policy Manager (CPPM), go to Configuration > Identity > Roles and create a role that matches the operator profile. Refer to the ClearPass Policy Manager documentation for information on creating the role. 3. Create a local user for the operator: In CPPM, go to Configuration > Identity > Local Users. Select the CPPM role defined for the user. Refer to the ClearPass Policy Manager documentation for information on creating the local user. 4. Create a translation rule to map the CPPM role name to the ClearPass Guest operator profile: In ClearPass Guest, go to Administration > Operator Logins > Translation Rules. 5. In the Translation Rules list, choose the profile, then click its Edit link. 6. Edit the fields appropriately to match the CPPM role name to the ClearPass Guest operator profile. See "LDAP Translation Rules " on page 254. 7. Click Save Changes. External Operator Authentication Operators defined externally in your company's directory server form the second type of operator. Authentication of the operator is performed using LDAP directory server operations. The attributes stored for an authenticated operator are used to determine what operator profile should be used for that user. The Manage Operator Servers and the Translation Rules commands allow you to set up operator logins integrated with a Microsoft Active Directory domain or another LDAP server. NOTE: The operator management features, such as creating and editing operator logins, apply only to local operator logins defined in ClearPass Guest. You cannot create or edit operator logins using LDAP. Only authentication is supported. 248 | Creating a New Operator Dell Networking W-ClearPass Guest 6.0 | Deployment Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320

248
| Creating a New Operator
Dell Networking W-ClearPass Guest 6.0 | Deployment Guide
Creating a New Operator
To create a new operator or administrator for ClearPass Guest or AirGroup, some steps are performed in ClearPass
Policy Manager (CPPM), and some steps are performed in ClearPass Guest, as described below:
1.
Create an operator profile in ClearPass Guest, or use an existing one. See
"Operator Profiles " on page 242
.
To create AirGroup users, choose either the AirGroup Administrator or AirGroup Operator profile, as appropriate.
These profiles are automatically included in ClearPass Guest when the AirGroup Services plugin is installed.
2.
Create a CPPM role for the operator: In ClearPass Policy Manager (CPPM), go to
Configuration > Identity >
Roles
and create a role that matches the operator profile. Refer to the ClearPass Policy Manager documentation
for information on creating the role.
3.
Create a local user for the operator: In CPPM, go to
Configuration > Identity > Local Users
. Select the CPPM
role defined for the user. Refer to the ClearPass Policy Manager documentation for information on creating the
local user.
4.
Create a translation rule to map the CPPM role name to the ClearPass Guest operator profile: In ClearPass
Guest, go to
Administration > Operator Logins > Translation Rules
.
5.
In the
Translation Rules
list, choose the profile, then click its
Edit
link.
6.
Edit the fields appropriately to match the CPPM role name to the ClearPass Guest operator profile. See
"LDAP
Translation Rules " on page 254
.
7.
Click
Save Changes
.
External Operator Authentication
Operators defined externally in your company’s directory server form the second type of operator. Authentication of
the operator is performed using LDAP directory server operations. The attributes stored for an authenticated
operator are used to determine what operator profile should be used for that user.
The
Manage Operator Servers
and the
Translation Rules
commands allow you to set up operator logins integrated
with a Microsoft Active Directory domain or another LDAP server.
NOTE: The operator management features, such as creating and editing operator logins, apply only to local operator logins
defined in ClearPass Guest. You cannot create or edit operator logins using LDAP. Only authentication is supported.