Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Another AAA profile user derivation rule question

This thread has been viewed 1 times
  • 1.  Another AAA profile user derivation rule question

    Posted Sep 22, 2016 03:43 PM

    Are there options to store user derivation rules within radius attributes or some other method of using them instead of entering them on the controller in the "user rules" section of the AAA profile?  I am setting options based on mac address before the user authenticates.

     



  • 2.  RE: Another AAA profile user derivation rule question

    EMPLOYEE
    Posted Sep 22, 2016 03:55 PM
    You would just simply return the role or VLAN via RADIUS. No need for UDRs.


  • 3.  RE: Another AAA profile user derivation rule question

    EMPLOYEE
    Posted Sep 22, 2016 04:19 PM

    @abowen500 wrote:

    Are there options to store user derivation rules within radius attributes or some other method of using them instead of entering them on the controller in the "user rules" section of the AAA profile?  I am setting options based on mac address before the user authenticates.

     


    The short answer is yes, but the long answer will depend on what you are using user rules for.  What are you using the user derivation rules for?

     



  • 4.  RE: Another AAA profile user derivation rule question

    Posted Sep 22, 2016 06:15 PM

    I'm using them to set vlan and user role based on the client mac address.



  • 5.  RE: Another AAA profile user derivation rule question

    EMPLOYEE
    Posted Sep 22, 2016 07:59 PM

    Are you using authentication via radius for users?  Why don't you set the VLAN by AD group, instead writing a rule for each mac address?



  • 6.  RE: Another AAA profile user derivation rule question



  • 7.  RE: Another AAA profile user derivation rule question

    Posted Sep 22, 2016 08:57 PM
    Prefer to use our perfectly capable Linux radius environment, our AD environment has proven to be inflexible by design and personnel. But I hear you.


  • 8.  RE: Another AAA profile user derivation rule question
    Best Answer

    EMPLOYEE
    Posted Sep 22, 2016 09:25 PM

    Okay, then you need to return the Aruba-User-Vlan Attribute to set the VLAN for users in your radius response.  If you are using Freeradius, you can import the Aruba VSA dictionary here:  https://support.arubanetworks.com/ToolsResources/tabid/76/DMXModule/514/EntryId/115/Default.aspx