Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Configuring nas-identifier in individual controllers

This thread has been viewed 2 times
  • 1.  Configuring nas-identifier in individual controllers

    Posted Sep 29, 2016 04:17 AM

    Hi,

    We've got a cluster of controllers (aruba0, arubal1 - arubal4) that are running ArubaOS 6.4.3.6. As normal, our RADIUS server configurations a rereplicated from the master controller down to all the local ones. Looking in my RADIUS accounting logs, I can see that the nas-ip-address matches up with the IP address of the controller sending rthe RADIUS auth request. However the nas identifier is always that of the master controller. This is correct because on aruba0 I've set the nas identifier to be "aruba0" and this gets pushed to all the other controllers. If I log onto a local controller , I can;t modify the nasidentifier as seen in a RADIUS server configuration because its read only. Is there any way of getting each local controller to advertise its own name as the nasidentifier instead of that of the master controller?

     



  • 2.  RE: Configuring nas-identifier in individual controllers

    Posted Sep 29, 2016 04:30 AM

    or do I just leave it blank and let the local controler fill in stuff itself?

     



  • 3.  RE: Configuring nas-identifier in individual controllers

    EMPLOYEE
    Posted Sep 29, 2016 04:31 AM

    One of the wireless SE can confirm but you should be able to go into the locals and configure the NAS ID otherwise it will take the setting from the master.

     

    Screen Shot 2016-09-29 at 3.30.51 AM.png



  • 4.  RE: Configuring nas-identifier in individual controllers

    Posted Sep 29, 2016 04:38 AM

    hmmm tried that. For 1 of our radius servers, removed the master controller settings for nasidentifier and pushed the config. Went to one of our local controllers and tried to edit that particular radius server nas identifier. It's greyed out, I can set the source interface but everything else in the temolate is read only. Re-adding the nasidentifier on the master and it apears on the local controller, again read only

     

    A



  • 5.  RE: Configuring nas-identifier in individual controllers

    EMPLOYEE
    Posted Sep 29, 2016 04:41 AM

    Not sure where it's located but one of other SE can chime in. I know there is a setting somewhere to override the NAS ID in the locals