AAA, NAC, Guest Access & BYOD

 View Only
last person joined: one year ago 

Solutions for legacy and existing products and solutions, including Clearpass, CPPM, OnBoard, OnGuard, Guest, QuickConnect, AirGroup, and Introspect

Management user in Aruba controller not receiving correct privilege level via TACACS authentication 

Jan 03, 2018 06:30 AM

Problem:

Management user in Aruba controller not receiving correct privilege level via TACACS authentication



Diagnostics:

Management user not receiving appropriate role /privilege while authenticating against ClearPass using TACACS

 

From the CLI of controller, when we check the privilege level for user: test , we see that root access is provided. From ClearPass access tracker log, we see that read-only access is returned.

 

 

From the pcap, we see the authentication is successful but do not see any TACACS authorization request received from Aruba controller to provide the appropriate privilege level to the management user: test

To enable TACACS authorization for TACACS server in the controller, navigate to Security > Authentication > Servers. Select the appropriate server configured for TACACS auth under TACACS server and enable "Session Authorization"

 

From pcap, we can now see that TACACS authorization request is sent from Aruba controller and ClearPass returns appropriate privilege level to management user: test

 

From CLI of controller, we can now see user: test getting the correct privilege level: read-only



Solution

"Session Authorization" option needs to be enabled in TACACS server configured in Aruba controller 

Statistics
0 Favorited
7 Views
0 Files
0 Shares
0 Downloads

Related Entries and Links

No Related Resource entered.