Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ArubaOS switches & ClearPass Radius & Aruba Central

This thread has been viewed 23 times
  • 1.  ArubaOS switches & ClearPass Radius & Aruba Central

    Posted Jan 28, 2022 11:50 AM
    Hi folks,

    Not sure where to post this since it touches all of the above but basically I noticed when adding a radius server in Aruba Central for an ArubaOS switch it gives you the option to say where the radius server ClearPass - see screenshot.  



    What affect does this have on the switch? and if not on the switch what's the benefit of defining this in Central? 

    The documentation did not provide any details. 

    Thank you!
    MG

    ------------------------------
    Cheers!
    MG
    ------------------------------


  • 2.  RE: ArubaOS switches & ClearPass Radius & Aruba Central
    Best Answer

    MVP GURU
    Posted Jan 28, 2022 11:57 AM
    From what I remember, you would need to enable this if you are using downloadable user roles. See here for the documentation on this piece: Configuring RADIUS Server Settings on AOS-S Switches

    And also here for explanation on the DUR side of that option: Configuring Downloadable User Role



    ------------------------------
    Dustin Burns

    Lead Mobility Engineer @Worldcom Exchange, Inc.

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2022
    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 3.  RE: ArubaOS switches & ClearPass Radius & Aruba Central

    MVP EXPERT
    Posted Jan 29, 2022 04:13 AM
    Hi
    If you’re configuring a 2940 switch , flagging the
    radius service as being clearpass allows you to set up device fingerprinting o the switch. Defining server as clearpass tells the switch which server(s) to upload discovered data to

    Might be a reason
    Rgds
    A
    Sent from my iPhone