ClearPass Insight
User Guide
Overview
ClearPass Insight is an advanced application for use with the ClearPass Policy Manager platform to deliver enhanced
analytics, in-depth reporting, and significant gains when addressing compliance and regulatory overhead. The goal of
this guide is to illustrate how easy it is for network managers to analyze authentication information captured from
Policy Manager in order to generate customized reports.
Custom report templates provide the ability to track detailed authentication records, audit trails, and systematic reports
on network-access trends, and to generate reports that are compliant with regulatory and corporate requirements.
Additional features associated with Insight are described below.
Consolidated Reporting
Insight is capable of aggregating data from multiple Policy Manager appliances, or external stores, containing archived
network access logs. It presents a powerful combination of near real-time analytics, as well as the ability to look into
the past to satisfy historical analysis and compliance needs.
In-depth Analytics
Insight uses a powerful analytics engine that mines network access logs in order to generate trending report on various
parameters. Network managers can utilize these trends to get an overview of authentication and access activity,
elaborate client access distribution, load-averages, and analyze authentication traffic flow through various network
devices.
Ready-to-use Templates
Insight includes several ready-to-use templates that help reduce the time associated with creating custom reports. The
templates guide users through the process of capturing data for a number of use cases with minimal configuration.
Alerts
Insight can generate near real-time alerts on anomalous network activity. Network managers can configure alerts based
on a number of various parameters. Alerts can be delivered via SMS or e-mail notification to multiple recipients to
prompt action.
Single Sign-on
Each application within the ClearPass suite can be accessed with a single login. Sign in once for access to Policy
Manager, Insight, Onboard, and Guest.
Getting Started
ClearPass Insight uses a Web-based management interface. The following browsers are supported:
l Mozilla Firefox 3.0 or newer
l Microsoft Internet Explorer 7.0 or newer
l Google Chrome 1.0 or newer
Logging In the First Time
1. Use one of the following methods to launch Insight.
0509012-02 | Sept 2013 1
l Point the browser to [Link]
l Access Policy manager by pointing the browser to [Link] and then select the
Launch ClearPass Insight application link. (See the image below.)
l Log in to Policy Manager, and then select Insight in the Dashboard > Applications widget. This opens Insight
in a new tab.
2. Use the default Username/Password [admin/eTIPS123], and then click Login to launch Insight.
Figure 1 Policy Manager Login Screen
Insight Dashboard
The Dashboard page opens immediately when you successfully log in. The Dashboard includes widgets that provide
a summarized, graphical view of your network analytics.
Figure 2 Insight Dashboard
2 ClearPass Insight User Guide | User Guide
All Authentications Widget
This widget provides of the number of authentications that have take place on your network over the last seven days.
Mouse over the graph to view the specific count.
Figure 3 All Authentications
Success vs Failed Authentications
This widget shows the number of successful and failed authentication attempts on your network over the last seven
days. Mouse over each line item in this chart to see the specific number of successful and failed authentications for a
specific day.
ClearPass Insight User Guide | User Guide 3
Figure 4 Successful vs Failed Authentications
Device Category
This widget provides a pie chart that summarizes the number of devices on your network based on the device type:
computer, smart device, etc. The data for the past seven days is displayed. Devices currently on the network are also
displayed. Mouse over each section to see the specific number of devices.
4 ClearPass Insight User Guide | User Guide
Figure 5 Device Category Widget
Top 10 Bandwidth Consumers
This widget displays a chart that shows the first top 10 bandwidth consumers.
ClearPass Insight User Guide | User Guide 5
Figure 6 Top 10 Bandwidth Consumers
Healthy vs Unhealthy Authentications
This widget shows the number of healthy and unhealthy authentication attempts on your network over the last seven
days. Requests that carry the health information, “system posture token” as healthy are constituted as healthy. Mouse
over each line item in this chart to see the specific number of successful and failed authentications for a specific day.
6 ClearPass Insight User Guide | User Guide
Figure 7 Healthy vs. Unhealthy Authentications
Service Categorization
The ClearPass Policy Manager policy model groups policy components that serve a particular type of request into
Service. This widget provides a chart that displays the usage of the services that used for different request types (for
example, 802.1X, Web Authentication).
ClearPass Insight User Guide | User Guide 7
Figure 8 Service Categorization
Guest Registrations
This widget shows the number of guest authentications on your network over a period of seven days. Mouse over the
chart to view the specific number of guest registrations for a given day.
8 ClearPass Insight User Guide | User Guide
Figure 9 Guest Registrations
Customize
The information provided in these widgets includes device connection and authentication attempts over the last seven
days. Use the Customize tool provided near the upper right portion of the Dashboard page to change the start time for
this seven-day range.
ClearPass Insight User Guide | User Guide 9
Figure 10 Customize
Search
Use the Search page to query the Insight database. Searches can be performed for all records, for specific reports, or for
specific alerts.
The Search Reports and Search Alerts template drop down menus are populated by currently configured reports and
alerts. If you have not yet configured reports or alerts, then the Select Template drop down for these options will be
blank.
Reports can be filtered using rules that include a simple AND or OR condition. For example, you can use rules specify
to view RADIUS Authentications from the Amigopod Active Directory or Guest User Repository source. When using
rules, the Value field auto-populates with data while you type.
Nested "AND/OR" combinations are not currently supported.
Configuring a Search
To perform a search:
1. Select the type of search to perform.
2. Select the template. Refer to the table that follows for a list of templates available when searching All Records.
3. If desired, specify rules to filter the search.
10 ClearPass Insight User Guide | User Guide
When you select either Search Reports or Search Alerts as the type, the Rules that are currently specified here will be
the rules used for processing the search.
4. Specify the desired date and time range. Note that you can search for data no just on a certain day, but for a
specific time as well.
5. Click Search when you are finished. The results of the search display in a table below the search criteria.
Figure 11 RADIUS Authentications for source Amigopod AD or [Guest User Repository]
The list of available Search templates includes:
l TACACS Failed Authentication
l Onboard Certificate
l ClearPass Configuration Audit
l Failed Application Authentication
l ClearPass Guest
l Onboard OCSP
l Failed Posture
l WEBAUTH Failed Authentications
l RADIUS Accounting
l ClearPass System Events
l Machine Authentication
l RADIUS Failed Authentications
l TACACS Authentication
l RADIUS Authentication
l Application Authentication
l WEBAUTH
l Onboard Enrollment
l Posture
Reports
The Reports page provides you with a method for creating reports that are tailored for specific network access data to
meet your precise requirements. Reports can be set up to run on the fly or can be scheduled daily, week, or monthly.
Insight reports show data over the last two-month period. In addition, Insight retains data for up to 2 years.
ClearPass Insight User Guide | User Guide 11
When configuring a report, you can specify rules that include a simple AND or OR condition. For example, you can
use rules specify to view RADIUS Authentications from the Amigopod Active Directory or Guest User Repository
source. When using rules, the Value field auto-populates with data while you type.
Nested "AND/OR" combinations are not currently supported.
After a report is configured and run, the report is available for download in PDF and CSV formats.
Adding and Running a Report
To add a report:
1. Navigate to the Reports page and select the Add Reports link.
2. On the Reports tab:
a. Enter a name and description for the report.
b. Enable the report. (Only Enabled reports can be run.)
c. Select to schedule the report at a specific time daily, weekly, or monthly. This will include all data for that
range. Alternatively, you can specify this as a static report rather than recurring, and then enter a time range for
data that you want to view.
d. Specify whether this is a private report, or whether all users will have access to download this report.
e. Enter an optional header and footer. Also, optionally enter an image that will appear on the report.
f. Specify an optional notification e-mail address and/or SMS number. If an e-mail address is configured, then a
PDF version of the report will be sent via e-mail. If an SMS number is configured, then an SMS message will be
sent to the specified phone number alerting that the report is available.
The SMS number must include the carrier information. In Policy Manager, navigate to the Administration > External
Servers > Messaging Setup page and select the Mobile Service Providers tab to view the list of supported carriers.
Figure 12 Add Reports > Reports tab
3. On the Configuration tab:
a. Select the template for this report. Refer to the table that follows for a list of available templates.
b. Specify analytical data to be included in the report. Use the Ctrl button to select multiple criteria.
c. If desired, specify rules to filter the search.
12 ClearPass Insight User Guide | User Guide
Figure 13 Add Reports > Configuration tab
4. On the Columns tab, determine the columns that you want to include in your report. Each Column Type includes
a list of available columns. Simply drag and drop a label from the Available Columns section to the Selected
Columns section to add it to the report. Similarly, you can drag columns out of the Selected Columns section and
move it back to Available Columns. You can also utilize dragging and dropping to sort the order of the selected
columns.
Figure 14 Add Reports > Columns tab
5. Click Save when you are finished. Upon successful completion, the new report will be available on the front
Reports page.
To run the report:
1. Select the check box beside the new report, and then click the Run Report button.
ClearPass Insight User Guide | User Guide 13
Figure 15 Running a Report
2. A message will display when the report is completed. Select the report that you just ran, navigate to the
Downloads tab, and select the report format that you want to view (PDF, HTML, or CSV). If a notification has
been set up, then a PDF version of the report will be sent to the specified e-mail address, and an SMS message will
be sent to the specified number.
Report Templates
The list of available Report templates includes:
l Session and NAS Information
l TACACS Failed Authentication
l Onboard Certificate
l ClearPass Configuration Audit
l Failed Application Authentication
l ClearPass Guest
l Onboard OCSP
l Failed Posture
l WEBAUTH Failed Authentications
l RADIUS Accounting
l License Information
l ClearPass System Events
l Machine Authentication
l RADIUS Failed Authentications
l TACACS Authentication
l Application Authentication
l ClearPass Guest Information
l WEBAUTH
l Onboard Enrollment
l Posture
l Unique Sessions
l Endpoints
l Session and Policy
l RADIUS Authentications
14 ClearPass Insight User Guide | User Guide
Alerts
Alerts provide network managers with near-real-time messages on anomalous network activity. Such activity could
constitute:
l Irregular authentication activity
l Irregular network device access activity
l Users attempting privileged commands on network devices
l Irregular activity on the ClearPass servers.
As with Reports, Alerts include templates for easy configuration. These templates allow managers to quickly configure
and monitor network activity. In addition to e-mail notifications, you can also send alerts to mobile devices via SMS,
providing the capability to receive mission-critical information on the go.
Adding Alerts
To add an alert:
1. Navigate to the Alerts page and select the Add Alerts link.
2. Enter a name and description for the alert.
3. Select the template for this alert. Refer to the table that follows for a list of available templates.
4. If desired, specify rules to filter the search. For example, you can specify to view RADIUS Authentications failures
from the Amigopod Active Directory or Guest User Repository source. When using rules, the Value field auto-
populates with data while you type.
Nested "AND/OR" combinations are not currently supported.
5. Specify threshold and interval values as criteria for determining whether an alert is necessary. For example, you may
want to set up an alert if authentication fails 10 times within five minutes. Note that Threshold has no maximum
value.
6. Specify a notification e-mail address and/or SMS number to be used when sending an alert.
The SMS number must include the carrier information. In Policy Manager, navigate to the Administration > External
Servers > Messaging Setup page and select the Mobile Service Providers tab to view the list of supported carriers.
Figure 16 Add Alerts
ClearPass Insight User Guide | User Guide 15
Alert Templates
The list of available Alert templates includes:
l WEBAUTH Failed Authentications
l TACACS Failed Authentications
l TACACS Command Execution
l ClearPass Policy Manager Services
l TACACS Failed Device Administration
l ClearPass Policy Manager SNMP Errors
l RADIUS Failed Authentications
Administration
The Administration page is used for configuring the e-mail server and settings to be used when sending notifications.
You can also specify the number of days for retaining information in you database. Finally, this page allows you to
test the new notification settings to review Insight log files.
Configuring Administration Settings
To configure notification and database settings:
1. Navigate to the Administration page.
2. Specify a hostname for the SMTP/e-mail server.
3. Specify the port on which this resides. This value defaults to 25. However, if SSL Required is specified, then this
value defaults to 465. Similarly, if Start TLS is specified, then this value defaults to 587.
4. Enter the administration user name and password.
5. Specify the timeout value in seconds.
6. If desired, specify either to require SSL or to start TLS.
7. Enter a valid e-mail address in the From Address field.
8. In the Database Retention field, specify the number of days to retain database records, reports, and alerts.
Figure 17 Administration
16 ClearPass Insight User Guide | User Guide
Testing the Notification Settings
When you have finished setting up the e-mail server, use the Test Notification Settings button on the lower-left
portion of the page to make sure that there are no errors in your configuration.
Collect Logs
Click on the Collect Logs button on the lower-left portion of the page. You will be prompted to either open or save
the file. The log files are stored in [Link] format.
ClearPass Insight User Guide | User Guide 17