Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

User role and tagged VLAN -HP Switch-

This thread has been viewed 35 times
  • 1.  User role and tagged VLAN -HP Switch-

    Posted May 26, 2021 07:12 PM
    Hello,

    I am deploying roles in my switches (HP 3500). My CPPM sent the role name to the switches and I am deploying a VLAN linked to the role in the switch configuration. All is working fine but when I want to set a tagged VLAN, I've not found a way to perform it with HP switches (K16.02 version).

    I have looking for information about it and I can see that inside role configuration, in Aruba switches there is a command to make that "vlan-id-tagged X" I've tried to configure it in my HP switches but they only give me the option of configure an untagged VLAN "vlan-id X". 

    Do you know if there is any way of configure a tagged VLAN linked to a user-role in HP switches with K16.02 versión?

    Thanks in advance.

    Best regards,

    ------------------------------
    tech_sec
    ------------------------------


  • 2.  RE: User role and tagged VLAN -HP Switch-

    EMPLOYEE
    Posted May 26, 2021 08:26 PM
    I don't think that's supported.

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------



  • 3.  RE: User role and tagged VLAN -HP Switch-

    Posted May 27, 2021 02:05 AM
    Thank you for your answer. Do you know if there is any other release for HP 3500 that supports this feature?

    ------------------------------
    tech_sec
    ------------------------------



  • 4.  RE: User role and tagged VLAN -HP Switch-

    Posted May 27, 2021 04:26 AM
    I don't have any direct experience of the HP3500 but on other legacy HP switches I have successfully used IETF (RFC4675) Egress-VLANID attribute - see https://community.arubanetworks.com/community-home/digestviewer/viewthread?MID=7032

    ------------------------------
    Derin Mellor
    ------------------------------



  • 5.  RE: User role and tagged VLAN -HP Switch-

    Posted May 27, 2021 06:42 AM
    Thank you Derin, yes, I've used it with legacy HP switches successfully. But in this specific scenario, I need to use "user-roles" in the own switch, then I need to configure the tagged vlan inside this role:

    aaa authorization user-role name {user-role name}
    policy {policy-name}
    vlan-id-tagged {vlan id}

    The problem is that these HP switches only give me the chance of use "vlan-id" and no "vlan-id-tagged" so I can only set untagged vlans.

    ------------------------------
    tech_sec
    ------------------------------



  • 6.  RE: User role and tagged VLAN -HP Switch-

    EMPLOYEE
    Posted May 28, 2021 09:01 AM
    You will need firmware 16.08 16.06 or up to get support for the vlan-id-tagged (or 16.08 for multiple tagged VLANs in a role). That probably is not a solution as the 3500 does not support that, but it is an explanation why it doesn't work.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 7.  RE: User role and tagged VLAN -HP Switch-

    Posted Jun 01, 2021 07:48 PM
    Thank you very much Herman

    ------------------------------
    tech_sec
    ------------------------------



  • 8.  RE: User role and tagged VLAN -HP Switch-

    Posted May 27, 2021 12:45 PM
    Can anyone recommend a good book (or educational video set) that covers VLAN's. I am interested in learning more about every aspect from the basic protocol to what the functions do and all the way up to how to configure network management hardware.

    ------------------------------
    Laisha Hermann
    ------------------------------



  • 9.  RE: User role and tagged VLAN -HP Switch-

    EMPLOYEE
    Posted May 28, 2021 08:57 AM
    Please open a new topic/thread. This question is off-topic to this question.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------