Wired Intelligent Edge

 View Only
  • 1.  Aruba AOS-CX – RADIUS Authentication with Microsoft NPS

    Posted Oct 17, 2021 04:02 PM

    Aruba AOS-CX – RADIUS Authentication with Microsoft NPS

     

    I have a requirement to use Microsoft NPS in Server 2019 for RADIUS management authentication with AOS-CX.  I have been having trouble finding updated documentation on configuring NPS to work with Aruba AOS-CX.

     

    I presently have the Microsoft NPS configured and working properly with our Aruba Controllers (and for other vendors) and everything is working fine.  I largely used this material (https://community.arubanetworks.com/community-home/digestviewer/viewthread?MID=10129) as a reference when I initially configured NPS to work with Aruba OS for the controllers. Unfortunately, nothing equivalent exists for NPS configuration for AOS-CX.

     

    What I would like to find out is what's the exact config in NPS's VSA configuration I should use in order to have the Network Policy for AOS-CX authenticate with a privilege level of 1 and 15 respectively.  What vendor code should I use for AOS-CX (I know for Aruba controllers is 14823)?  I would also need to know what the vendor assigned attribute number is, format, and Attribute Value. See below screen shot of the Vendor Specific Attribute Information & Configure VSA.  This is what I am referring to for the information I need to so I can fill these parts out correctly.  There may be multiple VSA's and/or other RADIUS Standard Attributes I need - I am just not sure though.

    Config VSA

     

    Any help or assistance that can be offered for the proper configuration of Microsoft NPS for AOS-CX would be greatly appreciated.  Thank you.



    ------------------------------
    Administrator Eronetix
    ------------------------------


  • 2.  RE: Aruba AOS-CX – RADIUS Authentication with Microsoft NPS

    Posted Oct 19, 2021 07:50 PM
    Howdy,

    The AOS-CX Vendor code is 14823 just like the controllers.

    To apply privilege levels to authenticated users, you'll need to define the following VSA in NPS:

    Attribute              Format           Value
    Aruba-Priv-Admin-User  Integer          3

    Now in your NPS Policy, you can pass back the Privilege level (eg: 1 or 15) in this VSA based on the user's role.




    ------------------------------
    Ben Dale
    ------------------------------



  • 3.  RE: Aruba AOS-CX – RADIUS Authentication with Microsoft NPS

    Posted Aug 09, 2024 12:02 PM
    Edited by jpb Aug 09, 2024 12:31 PM

    I found that you have to remove the Standard Radius Attributes as it will try to match on that first. The configuration of the Vendor Specific Attribute should look like this:

    So Standard is blank

    and Vendor Specific looks like this after you configure it:

    This results in the following Access-Accept from NPS:

    From the AOS-CX 10.10 Security Guide on RADIUS: