Network Management

last person joined: yesterday 

Keep an informative eye on your network with HPE Aruba Networking network management solutions
Expand all | Collapse all

Airwave and freeRADIUS - Airwave not logging despite valid role response from RADIUS

This thread has been viewed 0 times
  • 1.  Airwave and freeRADIUS - Airwave not logging despite valid role response from RADIUS

    Posted Jun 15, 2017 06:59 AM

    Hello all,

     

    I have followed this guide and have debugged freeRADIUS. freeRADIUS authenticates the request from Airwave and sends an access-accept but Airwave does not like it and log me in.

     

    Questions, with details below...

     

    What should the role be in the freeRADIUS config, "AMP Administrator" or "AMP Administration"? At present neither works.

     

    I can ssh in to airwave and looking at the auth logs for CentOS with

    utmpdump /var/log/wtmp*

    this only has entries for root and tries against freeRADIUS for root. Is there a log that I can look at in AirWave to see why the it isn't accepting the valid response from freeRADIUS?

     

    Article followed

     

    https://community.arubanetworks.com/t5/Monitoring-Management-Location/Configuring-FreeRADIUS-to-authenticate-AWMS-Users/ta-p/168920

     

     

    From freeRADIUS debug:

     

    +} # group post-auth = ok

    Sending Access-Accept of id 106 to AIRWAVEIP port 38488
    Aruba-Admin-Role = "AMP Administration"

     

    OR

     

    As per Airwave's role type field

    +} # group post-auth = ok

    Sending Access-Accept of id 110 to AIRWAVEIP port 38488
    Aruba-Admin-Role = "AMP Administrator"

     

    The section of the users file

     

    DEFAULT LDAP-Group == "someGroup", Client-IP-Address =~ "^AIREWAVEIP", Auth-Type := Kerberos
    Aruba-Admin-Role = "AMP Administrator",
    Fall-Through = No

     

    DEFAULT Client-IP-Address =~ "^AIRWAVEIP", Auth-Type := REJECT
    Fall-Through = No

     

    Why I am wondering if the role type is different from the documentation.

    airwave role.PNG

     

    Thank you in advance

     

    Komorebi



  • 2.  RE: Airwave and freeRADIUS - Airwave not logging despite valid role response from RADIUS
    Best Answer

    Posted Jun 15, 2017 07:09 AM

    Solution:

     

    The role "AMP Administration" needs to be created in Airwave.

     

    AMP Setup > Roles

     

    Add role.

     

    Set the type to be "AMP Administrator"

     

    Give it a name and click Add, to create a role with the default settings.

     

    This is the extra step that is needed for the guide here:

     

    https://community.arubanetworks.com/t5/Monitoring-Management-Location/Configuring-FreeRADIUS-to-authenticate-AWMS-Users/ta-p/168920

     

     



  • 3.  RE: Airwave and freeRADIUS - Airwave not logging despite valid role response from RADIUS

    Posted Sep 01, 2017 09:31 AM

    Hi guys, I'm trying to connect Airwave to Splynx Radius software - https://splynx.com, I think it's also FreeRadius based.

    Is there available any general Radius setup guide ? 

     

    thanks,