is there any way to get MPSK working without Clearpass? We are working with FreeRADIUS (where we can configure custom attributes) and do not plan to use Clearpass in the future.
No, Clearpass is a requirement for Aruba MPSK.
Isn´t MPSK on the Radius side not much more than sending a VSA to the controller that has the PSK for the client?
Aruba-mPSK-Passphrase seems to be the VSA name.
CPPM is required to support Aruba MPSK.
May I ask why?
Couldn´t I setup freeRadius in a way that it will send back the mPSK on a per device/group basis?
Controller will do a MAC auth against freeRadius and freeRadius can add the VSA when it is set back to the controller?
I would also like to know why I am not allowed to use a different Auth-Server for this.
It seems I cant't configure MPSK with a FreeRADIUS Server, it simply recieves no requests when configuring it as a MPSK Auth-Server.
OK, we now got FreeRadius talking to our controllers. We are setting the correct "Aruba-MPSK-Passphrase" VSA, but the controllers are still complaining that it is missing ("Aruba-MPSK-Passphrase VSA not received for MPSK user - MAC cc:2f:xx:xx:xx").
OK, i found out how the VSA has to be used to get MPSK working without CPPM. I will write up how to do this in a blog post in a few days.
Hi,May I please know how could you set up the MPSK without the CPPM?Many thanks,
At Aruba, we believe that the most dynamic customer experiences happen at the Edge. Our mission is to deliver innovative solutions that harness data at the Edge to drive powerful business outcomes.
© Copyright 2021 Hewlett Packard Enterprise Development LPAll Rights Reserved.