Do you see any errors or messages related to the role download in the CX switch logging?
You probably should start by changing the IP addresses (10.16.20.31/32) to the FQDN which should be resolvable in DNS or through a ip dns host statement in your switch.
The switch will reach out to your ClearPass and the ClearPass HTTPS server certificate should match the fqdn and should be issued by the root CA that you imported as trust anchor. It's likely that the IP address is not part of the ClearPass server certificate and the SSL/HTTPS connection to download the certificate will not even come up. That should be logged as well in the switch.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Feb 19, 2025 01:32 AM
From: jc185213
Subject: Clearpass downlaodable user role 6300F
Hi trying to configure a dowloadable user role
clearpass version 6.9.13
swtich 6300F version 10.07.0030
here's my switch and clearpass config. It works on local user role but the downloadble does not get pushed to the switch. Anything I'm missing?





