Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Operator login

This thread has been viewed 5 times
  • 1.  Clearpass Operator login

    Posted Sep 13, 2017 04:18 PM
      |   view attached

    Hi All,

     

    I am in need of some assistance to setup authentication to Clearpass guest for a receptionist so they only have access to guest.

     

    This is so they can create guest users for devices that connect to their Aerohive wireless.

    I have created the account in the local user database. I have documented the rest of the configuration for you so you can advise me where I have gone wrong.

    Please see attached.

     

    Can you please advise me where my configuration has gone wrong?

    I see the correct application service is being hit, but the authentication source, roles or enforcement do not get populated.

    I get this alert on the access tracker:

     

    [Local User Repository]: Failed to execute sql, reason=ERROR: syntax error at or near test"
    Position: 1"

    Attachment(s)



  • 2.  RE: Clearpass Operator login

    Posted Sep 13, 2017 04:27 PM

    Looks like an SQL error in the local user auth source. Did you modify the [Local User Repository] auth source at all?



  • 3.  RE: Clearpass Operator login

    Posted Sep 13, 2017 04:31 PM

    Also give it a try with the [Admin User Repository]



  • 4.  RE: Clearpass Operator login

    Posted Sep 14, 2017 04:17 AM

    Nope I just created an account under identity > local users section in Clearpass, added username and password and associated a role to the account.

    I did also try the admin user repository but in the access tracker got the error: user not found in admin user repository.

    I got a bit further this morning as I forgot to enable authorization in the service. I enabled this and found that the authorization source has now been populated with local user repository.  However, the roles is still hitting other and enforcement is still default deny access. I still get this error as the alert:

    [Local User Repository]: Failed to execute sql, reason=ERROR: syntax error at or near test"
    Position: 1"

     

    Any other ideas on how to proceed further with this?



  • 5.  RE: Clearpass Operator login

    Posted Sep 14, 2017 04:39 AM

    I have managed to resolve the issue. 

    I found the following things that I did not do right initially:

    - Authorization was not enabled on the service. 

    - I was logging in with the wrong username for the account that I setup in the local user repository. I was using the name instead of the user-id. Note for the future for me. 



  • 6.  RE: Clearpass Operator login

    Posted Feb 01, 2018 08:02 AM
      |   view attached

    Hi,

     

    I have almost similar problem, but is Authorization enabled and login name is ok. Can you please check my configuration ?

     

    ClearPass version is 6.7.0.35289.

     

    Thanks 

    Attachment(s)

    docx
    CP-Operator.docx   539 KB 1 version


  • 7.  RE: Clearpass Operator login

    Posted Feb 01, 2018 08:15 AM


  • 8.  RE: Clearpass Operator login

    Posted Feb 01, 2018 09:12 AM

    do you have authorization enabled on the service?

     



  • 9.  RE: Clearpass Operator login

    Posted Feb 01, 2018 09:17 AM

    Yes, Authorization is enabled. As it is in the word file on page 4.



  • 10.  RE: Clearpass Operator login

    Posted Feb 01, 2018 09:40 AM

    oh sorry missed the attachement. Can you send me the summary tab of the access tracker when you try and login?



  • 11.  RE: Clearpass Operator login

    Posted Feb 01, 2018 09:47 AM
      |   view attached

    Authorization is successfull. But the admin_privileges parametr is not change. it is still the same as the local user role (test123).

     

    Summary tab is attached.