Monitoring Central NAC

The view switcher card is present in the Central NAC page and facilitates to navigate between the Central NAC Monitoring and Configuration views.

When you click the Summary icon in the View Switcher card, the Central NAC Monitoring cards are displayed. The following list provides a short description of the Central NAC monitoring cards:

  1. Time Travel Widget—The Time Travel Widget provides a time scope of 3 hours, 1 day, and 7 days. Based on the selected time range, data is displayed in the Central NAC monitoring dashboard. By default, the time range is set to 3 hours. The vertical lines in the widget indicate the time stamp of when the events occurred. The widget displays the following labels on its left pane:

    • Config—shows policy updates in the Central NAC

    • Accept—shows all successful authentications

    • Reject—shows rejected authentications

    When you choose a particular time range in the time travel widget, all cards in the global dashboard are updated except for the Identity Store card.

  2. Authentication Requests—This card displays the authentications over time. This card provides different views in terms of the following options:

    • All

    • Users

    • Clients

    • Visitors

    The card displays 2 line charts, one for Accepted requests, and the other for Rejected requests. The x-axis displays the selected time window and y-axis displays the number of authentications.

  3. Authentication Requests by Type—This card displays the total number of authentication requests for All, Clients, Visitors, and Users in the selected time window.

  4. Top Sites by Authentications—This card displays the list of sites and the corresponding authentications broken down by Accepted or Rejected. The list of sites is sorted, displaying the site with the most authentications at the top.

  5. Identity Store—This card displays the current status of identity stores. The identity management table lists the Name, Provider, and Status of the identity store. The Status column displays the health status of the identity store:

    • Unknown (gray square)—when the status is not determined

    • Healthy (green dot)—when the user group is fetched successfully

    • Error (red diamond)—when there is an error fetching the user group

  6. Authentication Requests Breakdown—This card displays the authentication request through different views like By Reject Reason or By Network.

Sites

  1. In the Central NAC landing page, click the Sites option in the left navigation pane.

    The Sites page is displayed.

    The Sites page displays a list of all sites including those sites that do not have any client authentications. The Sites page lists the Name, Clients authenticated, and number of Authentications.

  2. Click on a Site name.

    The Site NAC Monitoring page is displayed.

    The Site NAC Monitoring page displays the following cards:

    • Authentication Requests

    • Authentication by Type

    • Authentication Breakdown

    Based on the selected time range in the time travel widget, the cards in the Site NAC Monitoring page are updated and changes are displayed in the Sites dashboard.

Clients

  1. In the Central NAC landing page, click the Clients option in the left navigation pane.

    The NAC Clients page is displayed.

    The NAC Clients page displays the clients authenticated through Central NAC. The clients are categorized under different columns, Name, Connection Type, MAC Address, IP Address, WLAN, and Role. These columns are displayed by default. The NAD Vendor column lists devices managed by a specific third-party NAD. This field can be added using the Customize Columns option as mentioned in step 7.

    The clients list can be filtered based on the fields such as Status, Connection Type, and Access Type. These are quick filters.

  2. Under Status, select Accepted or Rejected.

    The clients list refreshes and displays either Accepted or Rejected entries.

    Similarly, you can select the options available under Connection Type and Access Type filters to view the specific clients list for these filters.

  3. Use the search bar to search for clients using Name, MAC Address, and IP Address fields.

    The clients' list displays entries that match the specific search term.

  4. Click the Filters icon.

    A pop-up window appears showing the following fields.

    The available options for Authentication Type are EAP-TLS, MPSK, MAC Authentication, Captive Portal, Air Pass, and Wi-Fi Easy Connect.

  5. Select one or more filters to narrow down information and click Apply.

    The clients list is populated based on the selected options in the filters panel.

  6. Click Clear Filters to remove the selected filters and restore the clients list.

    You can also create a combination of filters by combining the filters with the quick filters.

  7. Click the Actions button and select the Customize Columns option.

    The Customize Columns pop-up window appears. The following additional fields are listed in the pop-up window:

    • Site

    • NAD MAC Address

    • Reject Reason

    • VLAN

    • Last Authentication

    • Authentication Type

    • NAD Vendor

    You can select or unselect specific fields and click Apply. The changes will appear in the NAC Clients table.

  8. Click Reset to Defaults to restore the columns.

    The columns are updated and displayed in the clients list. You can also drag the column border to manually resize columns in the clients table.

  9. To reset the column size, from the Actions button select Reset Column Sizes option.

    The columns are restored to its original width.

  10. Hover over a column name and click the sorting icon.

    The clients list is sorted based on the specific column.

Client Details

  1. In the HPE Aruba Networking Central landing page, click the Clients option in the left navigation pane.

    The NAC Clients page is displayed.

  2. Click on a client name.

    The Client Details page is displayed. The following cards appear for a client:

    1. Authorization— Displays the last known authorization details as of end date (determined by the time travel widget).

      The Authorization card displays the following details:

      • User groups— displays the user groups that have the same set of access and permissions.

      • Assigned Role— displays the role assigned to the user.

      • Matching Policy— displays the name of the authorization policy that matches with the client's identity. When you click the policy name, it redirects you to the corresponding authorization policy page.

      • Matching Rule— displays the name of the authorization rule associated with the client's policy. If the authentication request matches a policy but does not match a rule, the Matching Rule displays Deny All. When you click the rule name, it redirects you to the corresponding authorization rule page.

      • Identity Store— displays the name of the client's identity store.

      Click the expand icon in the Authorization card to view the Attributes section as shown below:

      The Attributes section displays the following details.:

      • VLAN ID

      • Session Timeout

      • Any third-party vendor attributes (if applicable)

      The attribute list shows a minimum of five rows. If additional attributes are present, they can be viewed by clicking the “Show N More” option, which expands the full list.

    2. Overview— Displays the client details summary.

      The Overview card displays the following details:

      • Status— displays the status of the client certificate, if accepted or rejected.

      • Last Authentication Time— displays the timestamp when the client was last authenticated.

      • IP Address— displays the IP address of the client.

      • MAC Address— displays the MAC address of the client.

    3. Authentication— Displays the latest authentication attributes.

      The Authentication card displays the following details:

      • Authentication Type—displays the type of authentication.

      • Air Pass Provider—displays the name of the air pass provider. This field is visible if the authentication type is Air Pass.

      • Certificate Status—displays one of the following statuses based on the authentication type and the status of the certificate.

        Note:

        The certificate status is displayed only if the authentication type is EAP-TLS.

        • Valid—is displayed with a green icon along with the expiry date and time of the certificate. To revoke the certificate, click the Revoke Certificate button. In the confirmation pop-up, click Revoke to confirm the action. The certificate status is updated and displays the date and time of revocation. The Revoke Certificate button is subject to RBAC, where the user must have Central NAC Create permission.

        • Revoked—is displayed with a red icon along with the date of the revoked certificate. The Revoke Certificate button is hidden.

        • Expired—is displayed with a red icon along with the date of the expired certificate. You will be able to revoke expired certificates also.

        • Unknown—is displayed if the status of the certificate cannot be determined.

    4. Connectivity— Displays the client connection flow to Central NAC.

      The Connectivity card displays the following details:

      • Client—Displays the client name.

      • SSID—Displays the network name - only visible when there is an SSID (e.g. no SSID displayed for wired).

      • NAD—Displays the NAD name and icon specific to the NAD device type.

      • Central NAC—Displays the Central NAC with the corresponding icon (connection between the NAD node and the Central NAC node must be a tunnel link).

    5. Classification— Displays the latest known classification of the client as of end date (determined by the time travel widget).

      The Classification card displays the following details:

      • Category—Displays the category assigned to the client.

      • Function—Displays the function type of the client. For example, a client function can be categorized to work on computers, video conferencing, checking access points, and so on.

      • Vendor—Displays the name of vendor.

      • Model/OS—Displays the model or OS of the client running at the site.

      • Tags—Displays how various clients are defined in the site. All tags are displayed in a single line. Additional tags are represented by an extra tag indicating the number of remaining tags.

    6. NAC Events— Displays the summary of the last 5 events (sorted from the most recent to the oldest).

      Click the expand icon to see more events within the time window determined by the time travel widget.

      The expanded Central NAC Events card displays all the events related records in a tabular format and are categorized under the following fields:

      • Occurred—Displays the date and time of the event.

      • Category—Displays the event category, if it is an Accounting or Authentication category.

      • Event—Displays the status of the event.

      • Connection Type—Displays the type of connection, wired or wireless.

      • Details—Displays the error message.

      Using the vertical scroll bar you can navigate through a large list of records. Click the Filters icon to view the Filters panel. You can select more filters and apply these to refine, sort, or narrow down data based on specific criteria.