Security

Reply
Aruba Employee
Posts: 2
Registered: ‎09-15-2015

Assign Tagged VLAN via Radius attribute using "HP-Egress-VLANID" parameter

Hi

 

Im trying to get Clearpass return HP-Egress-VLANID attribute to indicate a TAGGED VLAN association for the client device.

 

According to RFC this value is in bits- http://wiki.freeradius.org/vendor/HP#procurve-port-authentication-special-features_dynamic-vlan-assignment_rfc-4675-multiple-tagged-untagged-vlan-assignment

 

ClearPass only accepts unsigned integer.. as indicated in its below error message.

 

Can someone guide me on how to set this attribute to return a vlan-301 as TAGGED?

 

VLAN301-error.JPG

 

Thanks

Ram

Aruba Employee
Posts: 2
Registered: ‎09-15-2015

Re: Assign Tagged VLAN via Radius attribute using "HP-Egress-VLANID" parameter

Got it working.. simply converted HEX into decimal value:

HEX 3100012D = DECIMAL 822083885

 

CP-2530(config)# sh port-access mac-based 23 client det

Port Access MAC-Based Client Status Detailed

Client Base Details :
Port : 23
Client Status : authenticated Session Time : 236 seconds
MAC Address : 00e0bb-22b814 Session Timeout : 0 seconds
IP : n/a

Access Policy Details :
COS Map : Not Defined In Limit Kbps : Not Set
Untagged VLAN : Not Set
Tagged VLANs : 301
Port Mode : 1000FDx
RADIUS ACL List : No Radius ACL List

 

Regards

Ram

MVP
Posts: 77
Registered: ‎03-09-2015

Re: Assign Tagged VLAN via Radius attribute using "HP-Egress-VLANID" parameter

Not working for me...

I can use decimal value and that VSA to send untagged vlan.. but doesn't seem to be working for tagged...  I think it's the switch.

It'd be great to get some radius debug from HPE OS.. do you have any clues ?

MVP
Posts: 77
Registered: ‎03-09-2015

Re: Assign Tagged VLAN via Radius attribute using "HP-Egress-VLANID" parameter

In retrospect.. mine's not working for untagged either...

MVP
Posts: 77
Registered: ‎03-09-2015

Re: Assign Tagged VLAN via Radius attribute using "HP-Egress-VLANID" parameter

I'm doing this on a brand new 2530, running Software revision  : YB.16.01.000..

FYI.. if anyone wants to pipe in and provide some feedback..

New Contributor
Posts: 2
Registered: ‎07-08-2016

Re: Assign Tagged VLAN via Radius attribute using "HP-Egress-VLANID" parameter

Instead of the HP-Egress-VLANID you can also use now "HPE-Egress-VLAN-Name = 1VOICE".

Use "1" in front of the Vlan name if you want to use a tag en use "2" for untagging.

attribute.jpg

 

 

 

MVP
Posts: 77
Registered: ‎03-09-2015

Re: Assign Tagged VLAN via Radius attribute using "HP-Egress-VLANID" parameter

I never commented back on this thread after I raised it..

I ended up finding out that I think the switch software needs to support RFC4675 to be able to support parsing RADIUS attribute tagged vlan id.

https://tools.ietf.org/html/rfc4675.

That was my issue at the time.. The HPE switch model explicitly lacked RFC4675 support, where as other models higher up in the portfolio did support it.

MVP
Posts: 77
Registered: ‎03-09-2015

Re: Assign Tagged VLAN via Radius attribute using "HP-Egress-VLANID" parameter

Aka, the 2530 does not support RFC4675.

Search Airheads
Showing results for 
Search instead for 
Did you mean: