
 View Only
  • 1.  Clearpass TACACS - Authentication fail

    Posted Oct 08, 2014 03:44 PM

    Hi Guys,


    I'm using the CPPM as a TCACS Server, authenticanting some different switches models .

    I'm having a problem specifically with an HP (H3C) switch. When I try to access this switch with username and password that is registered in CPPM internal base, I receive the information from CPPM that the autehntication was accepted, but the switch reject the access.


    I have no problem with the others switches ( Ciscco and Dell).


    Is there something that I need to configure in the CPPM specically for HP (H3C) switches?


    Thanks i advance.


    Leandro Surcin

  • 2.  RE: Clearpass TACACS - Authentication fail

    Posted Oct 08, 2014 03:51 PM
    Youneed to send back a privilege level of 15. Create a new enforcement profile and add it to your policy.

  • 3.  RE: Clearpass TACACS - Authentication fail

    Posted Oct 08, 2014 04:05 PM

    HP ProCurve config:


    aaa authentication login privilege-mode
    aaa authentication ssh login tacacs local
    aaa authentication ssh enable tacacs local
    tacacs-server host key Pr0Curve




    Enforcement profile:





    Enforcement policy:



  • 4.  RE: Clearpass TACACS - Authentication fail

    Posted Oct 20, 2014 03:34 PM



    Its an HP 5120 switch model from H3C and I already configured the enforcement profile privilege level 15.


    Do you have some other advice?



  • 5.  RE: Clearpass TACACS - Authentication fail
    Best Answer

    Posted Oct 20, 2014 04:28 PM

    Have you set super password?


    [CS01]super password level 3 cipher ?
      STRING<1-53>  Ciphertext password string
    [CS01]super password level 3 cipher yoursecretkey

     then after you authenticate at level 0, type "super" to get to level 3

    Please input the password to change the privilege level. Press CTRL_C to abort.
    User privilege level is 3, and only those commands can be used
    whose level is equal or less than this.
    Privilege note: 0-VISIT, 1-MONITOR, 2-SYSTEM, 3-MANAGE


  • 6.  RE: Clearpass TACACS - Authentication fail

    Posted Oct 20, 2014 05:34 PM



    Its an HP 5120 switch model from H3C and I already configured the enforcement profile privilege level 15.


    Do you have some other advice?



  • 7.  RE: Clearpass TACACS - Authentication fail

    Posted Feb 12, 2018 06:03 AM

    Did you ever get to the bottom of this?