Wired Intelligent Edge

 View Only
last person joined: yesterday 

Bring performance and reliability to your network with the Aruba Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of the ArubaOS-Switch and ArubaOS-CX devices, and find ways to improve security across your network to bring together a mobile first solution.
Expand all | Collapse all

Failed to apply user role

This thread has been viewed 21 times
  • 1.  Failed to apply user role

    Posted Apr 01, 2023 11:29 PM

    Aruba 2930M-48G-PoE+ Switch (JL322A)
     Software revision  : WC.16.11.0010 

    Upgraded from WC.16.11.0008 to WC.16.11.0010 , reboot and DUR started failing :
     05204 dca: ST1-CMDR: Failed to apply user role
                Medo__VL_41__Voice__DUR-3185-7_7Z4q to macAuth client XXXXXXXX
                on port 2/21: user role is invalid.

    Switch# sh user-role download detail
    Downloaded user roles are preceded by *

    Checked ntp and communication with Clearpass and was ok.
    The DUR name on clearpass is less than 52 chars.
    What could stop the role from being downloaded?



  • 2.  RE: Failed to apply user role

    Posted Apr 02, 2023 10:27 AM

    Hi, sometimes when you're typing the rules into the role in Clearpass there could be a typo(hard to see a lot of times) in the acls which make the syntax bad and the role won't be applied.

    Can you show us how are you creating the role in Clearpass?

    I hope this helps




  • 3.  RE: Failed to apply user role

    Posted Apr 02, 2023 02:49 PM

    the same configuration is working for switches running WC_16_11_0007
    I believe the issue resides on https communication with clearpass.




  • 4.  RE: Failed to apply user role

    Posted Apr 03, 2023 09:08 AM

    Hi, have you imported the Clearpass CA cert as trust anchor or use the word clearpass in the radius server host command?

    This link shows how to import the cert: https://community.arubanetworks.com/community-home/digestviewer/viewthread?MID=34185

    This links show how to configure the radius server: https://www.flomain.de/2022/06/aruba-downloadable-user-roles/

    another thing, have configured:

    ip source-interface


    I hope this helps




  • 5.  RE: Failed to apply user role

    EMPLOYEE
    Posted Apr 04, 2023 10:37 AM

    If you just see 05204 dca: ST1-CMDR: Failed to apply user role
                Medo__VL_41__Voice__DUR-3185-7_7Z4q to macAuth client XXXXXXXX
                on port 2/21: user role is invalid.
    in the logging, it looks like the switch is not even trying to download the role, but is looking for a local user role (that does not exist).

    You can either increase the log verbosity or enable debugging for port-access/DUR/RADIUS and find the issue yourself, or open a TAC Case and let TAC find the issue.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 6.  RE: Failed to apply user role

    Posted Apr 04, 2023 12:22 PM

    please find bellow some more information :


    I believe that there is an issue with the EC certificate because the DUR is starting download but never completes due to handshake failure.
    I'm in between Switching and Clearpass TAC team who are disputing where the issue resides.
    Any thoughts ?




  • 7.  RE: Failed to apply user role

    EMPLOYEE
    Posted Apr 05, 2023 02:51 AM

    Based on CERT_INVALID_KEY Usage, can you share the HTTPS certificate that you have on your ClearPass? It looks self-signed, a CA certificate, or not for Server Authentication.
    If you are on ClearPass 6.10 or 6.11, make sure that if you have an ECC HTTPS certificate, that the RSA HTTPS certificate is disabled. And if you have an RSA HTTPS certificate, make sure the ECC Cert is disabled. If you have both enabled, and one is a default/self-signed, depending on the firmware version/OS, the switch may prefer RSA or ECC, which can be the wrong one. Most modern webbrowsers prefer ECC if both are available.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 8.  RE: Failed to apply user role

    Posted Apr 05, 2023 03:44 AM

    The certificate is ECC and RSA is disabled.Cpass version is 6.11.2.252294
    I noticed that the switch is trying to download the DUR from :
    https://10.YY.0.XX/async_netd/arubacppmapi/downloadableconfig?role=Medo__VL_41
       __Voice41__DUR-3249-1

    It's the IP of the Clearpass VIP instead of DNS name , as specified on radius config.
    Maybe this is the drawback?






  • 9.  RE: Failed to apply user role

    EMPLOYEE
    Posted Apr 05, 2023 05:10 AM

    Can you try to change your radius/clearpass configuration on the switch to use the fqdn instead of the IP address?
    BTW, I would have expected this to be documented if there was a change between WC.16.11.0008 and WC.16.11.0010, but could not find anything.
    If configuring the fqdn (hostname of your clearpass) does not work, it may make sense to open a support case as it's strange that the behavior changes between such a small firmware step and not seeing anything documented in the release notes.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 10.  RE: Failed to apply user role

    Posted Apr 05, 2023 05:56 AM

    Can you try to change your radius/clearpass configuration on the switch to use the fqdn instead of the IP address?
    This is exactly what i have done but i did not notice any change.
    I have an open Ticket and trying to coordinate a session with WC and Clearpass team altogether.
    Wish me luck!




  • 11.  RE: Failed to apply user role

    MVP EXPERT
    Posted May 02, 2023 10:06 AM

    I'm having the same problem, same  error message except the  DUR is being downloaded to the switch.
    It all used to work, even reverted from the wc.16.11 branch back to  WC.16.10.24 still does it.

    Have deleted all the downloadable user roles on the switch and they come back in and a  sh user-role down det shows  the downloaded user role


    Whats the command to increase verbosity of debug .. to see what its doing? or to specificall track DUR issues?

    A