Cloud Managed Networks

 View Only
  • 1.  Clearpass downlaodable user role 6300F

    Posted Feb 19, 2025 02:38 AM

    Hi trying to configure a dowloadable user role

    clearpass version 6.9.13

    swtich 6300F version 10.07.0030

    here's my switch and clearpass config. It works on local user role but the downloadble does not get pushed to the switch. Anything I'm missing? 



  • 2.  RE: Clearpass downlaodable user role 6300F

    Posted Feb 19, 2025 02:45 AM

    Do you see any errors or messages related to the role download in the CX switch logging?

    You probably should start by changing the IP addresses (10.16.20.31/32) to the FQDN which should be resolvable in DNS or through a ip dns host statement in your switch.

    The switch will reach out to your ClearPass and the ClearPass HTTPS server certificate should match the fqdn and should be issued by the root CA that you imported as trust anchor. It's likely that the IP address is not part of the ClearPass server certificate and the SSL/HTTPS connection to download the certificate will not even come up. That should be logged as well in the switch.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Clearpass downlaodable user role 6300F

    Posted Feb 19, 2025 04:56 AM

    also check the output of "sh port-access clients" and "sh port-access clients detail" to see why it is failing.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 4.  RE: Clearpass downlaodable user role 6300F

    Posted Feb 20, 2025 01:22 AM

    Yeah. I tried the FQDN as well but it's still not working. DNS and NTP on switch is working. 




  • 5.  RE: Clearpass downlaodable user role 6300F

    Posted Feb 20, 2025 01:24 AM

    Hmmm..Getting this error. 




  • 6.  RE: Clearpass downlaodable user role 6300F

    Posted Feb 20, 2025 02:17 AM

    So i change the ACL to port numbers instead of https/http/dns and that seemed to work. stange coz in local user role, when i do the https/http/dns instead of port numbers it still works. 




  • 7.  RE: Clearpass downlaodable user role 6300F

    Posted Feb 21, 2025 01:48 AM

    This looks like a difference between CLI parser and REST API.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 8.  RE: Clearpass downlaodable user role 6300F

    Posted Feb 21, 2025 05:08 AM

    I would also recommend to use recent software versions as in CX a lot of progress is taking place regarding all kinds of features but especially for port authentication! 



    ------------------------------
    Greez,
    Uli
    ------------------------------



  • 9.  RE: Clearpass downlaodable user role 6300F

    Posted Feb 21, 2025 05:59 PM

    you can use LSR firmware 10.13.1080



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------