last person joined: 5 hours ago 

Enterprise security using ClearPass Policy Management, ClearPass Security Exchange, IntroSpect, VIA, 360 Security Exchange, Extensions and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Critical authentication

Jump to Best Answer
This thread has been viewed 33 times
  • 1.  Critical authentication

    Posted May 20, 2021 06:09 AM

    I'd like to deploy a critical authentication feature to HPE and Aruba (ArubaOS) switches. I've been checking the configuration guide and I've found only one way to perform it using the roles configured in the switch:

    1. Assign a user-role containing untagged VLAN as critical-role using the command aaa port-access <port> critical-auth user-role <ROLE-NAME>

    Using this feature, I understand that devices connected to the ports configured with this command, are going to get access to the network and they'll receive the vlan inside the role configured always that CPPM server be unreachable.

    I've seen that Aruba with AOS-CX switches can perform this feature with more options:

    aaa authentication port-access [critical-role|preauth-role|reject-role|auth-role] <ROLE-NAME>

    Specifies the role that is applied when the RADIUS server is unreachable for authentication or when there is a request timeout.


    Specifies the role that is applied when authentication is still in progress.


    Specifies the role that is applied when authentication has failed.


    Specifies the role that is applied to authenticated clients when a specific role is not assigned in the RADIUS server.


    Specifies the role name.

    I'd like to deploy this feature when CPPM servers will be unreachable and in specific switches, when the authentication process will fail. With ArubaCX OS I could make that using the "reject-role" parameter. Do you know a procedure to perform this feature with ArubaOS and HPE switches?

    Thanks in advance.


  • 2.  RE: Critical authentication

    Posted May 20, 2021 04:01 PM

    Critical and open authentication is available on ArubaOS switch

    PowerArubaSW : Powershell Module to use Aruba Switch API for Vlan, VlanPorts, LACP, LLDP...

    PowerArubaCP: Powershell Module to use ClearPass API (create NAD, Guest...)

    PowerArubaCX: Powershell Module to use ArubaCX API (get interface/vlan/ports info)..

    ACEP / ACMX #107 / ACDX #1281

  • 3.  RE: Critical authentication

    Posted May 26, 2021 07:02 PM


  • 4.  RE: Critical authentication
    Best Answer

    Posted May 20, 2021 04:19 PM

    On ArubaOS-Switch you have two options:
    - Open Authentication - access before authentication
    - Critical Authentication - access when Radius is not reachable

    Unfortunately, you can only use open authentication for mac-auth.

    There is one more options, you can use "unauth-vid", which is similar for Open Authentication. 

    You can read more from docs, page 453 -
    About "unauth-vid" check page 639


    Piotr Filip


  • 5.  RE: Critical authentication

    Posted May 21, 2021 02:54 AM
      |   view attached
    I looked at this a couple of years ago, it might have changed since then.
    Have a look at the attached presentation slide 115-126

    Derin Mellor


  • 6.  RE: Critical authentication

    Posted May 26, 2021 07:03 PM
    Thank you for this presentation Derin, I can get a lot of information from it.


  • 7.  RE: Critical authentication

    Posted May 26, 2021 07:02 PM
    Thank you Piotr


  • 8.  RE: Critical authentication

    Posted Jun 01, 2021 08:31 PM
    Thank you Piotras, 

    about the unauth-vid, can it be only used with Mac-auth?

    Thanks in advance.