Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Cleapass CoA to Enterasys switch (B5)

This thread has been viewed 9 times
  • 1.  Cleapass CoA to Enterasys switch (B5)

    Posted Dec 08, 2016 01:25 PM

    Hi,

     

    I've been working through configuring Clearpass to Auth our Extreme (formerly Enterasys) B5 switches.  I have jsut about everything working except for CoA.  Does anyone know how to innitiate a CoA to one of those switches?

     

    Thanks

     

    --B



  • 2.  RE: Cleapass CoA to Enterasys switch (B5)

    Posted Jan 23, 2017 02:22 PM

    Same here - if I have the MIB to send a CoA to an Enterasys switch, how can I incorporate that into clearpass?



  • 3.  RE: Cleapass CoA to Enterasys switch (B5)

    EMPLOYEE
    Posted Jan 23, 2017 02:32 PM
    MIBs are not used with RADIUS.

    Did you try using the IETF COA template?


  • 4.  RE: Cleapass CoA to Enterasys switch (B5)

    Posted Jan 23, 2017 02:36 PM

    Perhaps I didn't phrase my question correctly - I'm trying to force reauthentication of a port on an Enterasys switch via Clearpass. I looked breifly at the IETF COA template but didn't have any luck in implementing it. I've found some MIBs that would allow setting a reauthentication on a switch port, but I'm not sure how I can call that from Clearpass.



  • 5.  RE: Cleapass CoA to Enterasys switch (B5)
    Best Answer

    EMPLOYEE
    Posted Jan 23, 2017 02:46 PM
    MIBs are used for SNMP based enforcement. Are you trying to use OnConnect?

    What happened when you used the standard IETF template?


  • 6.  RE: Cleapass CoA to Enterasys switch (B5)

    Posted Jan 23, 2017 04:13 PM

    We're actually making progress with the IETF Radius CoA to the Enterasys switch. It now seems to be a matter of correctly configuring the Enterasys switch to allow Clearpass as an RFC 3576 server so it will accept the CoA.



  • 7.  RE: Cleapass CoA to Enterasys switch (B5)

    EMPLOYEE
    Posted Jan 23, 2017 04:15 PM
    Yes you need to configure ClearPass as a dynamic authorization client.


  • 8.  RE: Cleapass CoA to Enterasys switch (B5)

    Posted Feb 01, 2017 12:45 PM

    It appears at first glance our switches (Enterasys B5) do not support RFC 3576 (based on a run-through of the supported specs for the switch). I'm thinking now my only option is the SNMP route. I've found a MIB I think will do the trick, but making that SNMP call from Clearpass is where I'm stuck.



  • 9.  RE: Cleapass CoA to Enterasys switch (B5)

    Posted Feb 14, 2017 08:38 AM

    I'm trying to add an SNMP Based Enforcement Profile but I don't see any option to specificy a specific SNMP MIB to perform a reauthentication on the switch. The only options I seem to have are VLANID and session options, which I'm not sure the switch is going to do anything with.