Wireless Access

 View Only
Expand all | Collapse all

cannot apply authenticated role without PEF

This thread has been viewed 47 times
  • 1.  cannot apply authenticated role without PEF

    Posted Sep 10, 2023 08:05 AM

    Dear All, 

    I have installed VMC and AP license only. When i create the SSID, i dont get option to change the role, its set to logon. When i got to AAA profiles and try to change it from there under initial role, it gives me below error. Why is this so? authenticated role is predefined right?

    Error: Role 'authenticated' is user defined, and can't be applied without Next Generation Policy Enforcement Firewall



  • 2.  RE: cannot apply authenticated role without PEF

    Posted Sep 10, 2023 08:25 AM
    You need PEF License if you want to create Roles. You can try to use default roles, it might work.

    ---------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP |
    -Just an Aruba enthusiast and contributor by cases-
    ---------------------------------





  • 3.  RE: cannot apply authenticated role without PEF

    Posted Sep 10, 2023 08:42 AM
    Thats what i am asking. Authenicated role is available by default so why its not letting me apply it. 

    If pef is not present we cant configure roles anyway





  • 4.  RE: cannot apply authenticated role without PEF

    Posted Sep 10, 2023 09:54 AM

    Did you modify the authenticated user role in any way?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: cannot apply authenticated role without PEF

    Posted Sep 10, 2023 09:57 AM
    No nothing is modified at all..

    Thats why i am confused why its calling it user defined





  • 6.  RE: cannot apply authenticated role without PEF

    Posted Sep 10, 2023 10:19 AM

    Been a long time since I ran anything without PEF (as PEF should be considered mandatory for operation) but I think one of the restrictions is the inability to modify the AAA profile to set a different initial or default role.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 7.  RE: cannot apply authenticated role without PEF

    Posted Sep 10, 2023 11:28 AM
    Well again the confusion is, why its considering authenticated as user defined role?





  • 8.  RE: cannot apply authenticated role without PEF

    Posted Sep 10, 2023 12:30 PM
    Edited by chulcher Sep 11, 2023 12:11 PM

    Are you using 802.1X to attempt to assign the 'authenticated' role?  That's default AAA profile and method is the only combination that results in 'authenticated' being applied.  You should also be able to return 'authenticated' via RADIUS. <RADIUS returned user roles (aka identity based access) are a feature of PEF>



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 9.  RE: cannot apply authenticated role without PEF

    Posted Sep 10, 2023 01:39 PM
    No i am using wpa2-personal.





  • 10.  RE: cannot apply authenticated role without PEF

    Posted Sep 11, 2023 11:48 AM

    Systems without PEF are quite rare, so it may be hard to get a proper answer.

    It seems that for some reason the system feels that the authenticated role has been modified. Depending on where you are in the process, doing a complete wipe (wr erase, or write erase all; please make sure you backup configuration AND licenses! as with write erase all licenses are also removed), and start over may be the quickest solution.

    If you have active support, you may open a TAC case as well.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 11.  RE: cannot apply authenticated role without PEF

    Posted Sep 11, 2023 11:52 AM
    Dear Herman,

    This is a lab setup and vmc is already on factory default. I just created a single ssid and encountered this problem





  • 12.  RE: cannot apply authenticated role without PEF

    Posted Sep 11, 2023 12:13 PM

    Looked around a little more, PEF specifically enables identity based access controls.  While the error message is a bit misleading, I'm betting it stems from your modification of the AAA profile as that also requires PEF.

    So, ANY modification of AAA profiles, user roles, ACLs, firewall policies, etc., requires PEF.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 13.  RE: cannot apply authenticated role without PEF

    Posted Sep 11, 2023 12:21 PM
    But i am able to apply role guest in aaa profile, why guest is allowed and authenticated is denied?





  • 14.  RE: cannot apply authenticated role without PEF

    Posted Sep 11, 2023 12:27 PM
    Have you modified any policy within the authenticated role?

    ---------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP |
    -Just an Aruba enthusiast and contributor by cases-
    ---------------------------------





  • 15.  RE: cannot apply authenticated role without PEF

    Posted Sep 11, 2023 12:36 PM
    Nope, if you require i can share the video of Factory reset vmc giving this error 





  • 16.  RE: cannot apply authenticated role without PEF

    Posted Sep 11, 2023 12:36 PM

    Not knowing exactly what you are doing, don't really know.

    But the short of it is that it sounds like you are trying to skate around needing PEF licensing, which isn't going to work out very well.  Some items are very strictly enforced, other items not so much, but at the end of the day PEF is required for just about anything having to do with identity or policy.  Start with the assumption that PEF is required (RFProtect is slightly more optional) and go from there.

    Thankfully we don't break out this functionality as a separate license level in AOS 10.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 17.  RE: cannot apply authenticated role without PEF

    Posted Sep 11, 2023 02:16 PM
      |   view attached

    Yes that is totally understood. 

    I have attached video also, just in case if you want to view. 

    I know without PEF, nothing much can be done




  • 18.  RE: cannot apply authenticated role without PEF

    Posted Sep 12, 2023 07:50 AM

    You try to change the initial role in your video. I think you can just leave the initial role as without PEF there should always be a role authenticated (or not even that), so whatever you apply should not be relevant.

    Have you tried with the unmodified settings what is the actual role that a client gets?



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 19.  RE: cannot apply authenticated role without PEF

    Posted Sep 12, 2023 08:08 AM

    The initial role as shown in the video also is logon. I have not tried connecting any client to this ssid, it would be strange if its getting authenticated?

     

    Best Regards

    Owais Iqbal

    CCIE | ACDX

    Technical Consultant - Aruba Networks

    Mob/Whatsapp: +92-321-2960496

     






  • 20.  RE: cannot apply authenticated role without PEF

    Posted Sep 12, 2023 08:39 AM

    Please try as that may not be that strange as without PEF there is no firewall enforcement.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 21.  RE: cannot apply authenticated role without PEF

    Posted Sep 12, 2023 10:43 AM

    Hi, Herman is right, without PEF license you cannot and should not worry about user-roles as you are not able to assign or modify them. 




  • 22.  RE: cannot apply authenticated role without PEF

    Posted Sep 12, 2023 01:44 PM
    Without ped we cant create new roles but if we want to assign builtin roles for that also do we need pef?





  • 23.  RE: cannot apply authenticated role without PEF

    Posted Sep 12, 2023 01:54 PM

    PEF is required for anything related to identity or policy.  Without PEF, count on anything under Roles, Policies, or Security to be default configuration only.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------