Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

problems with Aruba Instant Cluster and Clearpass DUR

This thread has been viewed 30 times
  • 1.  problems with Aruba Instant Cluster and Clearpass DUR

    Posted Feb 17, 2021 04:15 AM
    Hello,

    we have an instant cluster running, with Instant OS version 8.6.0.4, the cluster is managed via Aruba Central.
    We have a Clearpass with version 8.9.4.x in our environment.
    On the Clearpass we have created a service for the IAP cluster for testing.
    A DUR profile was created on the Clearpass, for testing we only used a simple setting we only pass VLAN 88...

    unfortunately the instant on the cli shows an error when downloading the role.

    I have created a user on the CPPM for the download and also loaded the cppm certificate on the Instant.



    does anyone else have an idea what the problem can be.

    Thanks a lot


    ------------------------------
    Tobi
    ------------------------------


  • 2.  RE: problems with Aruba Instant Cluster and Clearpass DUR

    EMPLOYEE
    Posted Feb 17, 2021 06:09 AM

    Hello, Can you share the error you obtain from CLI?

     

     

     

    --------------

    Jorge Calvi

    --------------

     

     






  • 3.  RE: problems with Aruba Instant Cluster and Clearpass DUR

    Posted Feb 17, 2021 07:07 AM
    Hi Jorge,

    here is the error

    I can connect to the ssid, but the traffic does not go to vlan 88


    ------------------------------
    Tobias
    ------------------------------



  • 4.  RE: problems with Aruba Instant Cluster and Clearpass DUR

    MVP GURU
    Posted Feb 17, 2021 09:46 AM
    What do you have on the log ? ( show log all..)

    ------------------------------
    PowerArubaSW : Powershell Module to use Aruba Switch API for Vlan, VlanPorts, LACP, LLDP...

    PowerArubaCP: Powershell Module to use ClearPass API (create NAD, Guest...)

    PowerArubaCX: Powershell Module to use ArubaCX API (get interface/vlan/ports info)..

    ACEP / ACMX #107 / ACDX #1281
    ------------------------------



  • 5.  RE: problems with Aruba Instant Cluster and Clearpass DUR

    EMPLOYEE
    Posted Feb 18, 2021 06:02 AM
    You cannot push the VLAN as part of the role. Instead, push a separate enforcement profile with Aruba-User-VLAN in addition to the Downloadable Role.

    Instant/ArubaOS: VLAN should be sent separately from the Downloadable User Role
    ArubaOS-Switch/AOS-CX: VLAN should be sent as part of the Downloadable User Role

    This may be confusing but works if you follow these guidelines.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------



  • 6.  RE: problems with Aruba Instant Cluster and Clearpass DUR

    Posted Feb 18, 2021 07:12 AM
    Hi Herman,

    thanks for your reply.
    Ok, this is my first time to do dur with instant aps. I´ve a CX Switch inviroment running with dur.

    I will test this tomorrow and give you an update.

    thanks

    ------------------------------
    Tobias
    ------------------------------