Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all
This thread has been viewed 8 times
  • 1.  CPPM TACACS

    Posted Feb 25, 2014 07:54 AM

    I'm trying to implement TACACS access to our Clearpass device using AD credentials. So far I have got an AUTHEN_STATUS_PASS and a role of [Aruba TACACS Root Admin]. However in the access tracker alerts there is a message "Tacacs server Tacacs service=cpass:http not enabled". What does this message indicate?



  • 2.  RE: CPPM TACACS

    EMPLOYEE
    Posted Feb 25, 2014 07:56 AM

    Under Administration > Dictionaries > TACACS+ Services, do you have the cpass:http dictionary?

     

    tacacs-dictionaries.PNG



  • 3.  RE: CPPM TACACS

    Posted Feb 25, 2014 07:58 AM

    Yes it's there in the list (number 5).



  • 4.  RE: CPPM TACACS

    EMPLOYEE
    Posted Feb 25, 2014 08:03 AM

    In your enforcement profile, do you have cpass:HTTP enabled in the Services tab?

     

    enf-tacacs-cpasshttp.PNG



  • 5.  RE: CPPM TACACS

    Posted Feb 25, 2014 08:12 AM

    This what I have under the profile -

    profile.png



  • 6.  RE: CPPM TACACS
    Best Answer

    EMPLOYEE
    Posted Feb 25, 2014 08:15 AM

    You'll need to duplicate the profile since it's a built in one. Then add the cpass:HTTP to the "Selected Services" box and then you can add in the appropriate attribute in the Service Attributes area.

     

    tacacs-cpasshttp.PNG



  • 7.  RE: CPPM TACACS

    Posted Feb 25, 2014 08:27 AM

    I've made the change and it all looks ok from the CPPM end (no errors shown) however the browser login page is showing "Invalid Username or Password specified"



  • 8.  RE: CPPM TACACS

    EMPLOYEE
    Posted Feb 25, 2014 08:30 AM

    If you are just trying to give Super Admin priveleges to ClearPass, try using the built-in [TACACS Super Admin] enforcement profile.



  • 9.  RE: CPPM TACACS

    Posted Feb 25, 2014 08:34 AM

    Sorry cappali, forgot to change the service attribute - I've now replaced it with one for the cpass:http with Super Administrator and its now working - thanks very much for your help.