Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

AAA authentication of CISCO NCS prime with Clearpass servers

This thread has been viewed 1 times
  • 1.  AAA authentication of CISCO NCS prime with Clearpass servers

    Posted Dec 10, 2013 03:16 AM
      |   view attached

    Hello guys,

     

    I'm trying to configure AAA in cisco ncs prime, which authenticates the AD user for its login.

     

    Already configured clearpass as TACACS server in prime NCS with shared secret, added prime NCS as network access device in clearpass, created a TACACS service in clearpass which authenticates againts AD.

     

    Now my question is what should be the enforcement profile pushed from the clearpass? We've many groups in ncs prime, each group has it own permissions and features.

     

    Tried to add in all task list in clearpass enforcement profile, as in attached pic, but I cant access the features in prime which is included in clearpass!!! :(

     

    Instead of sending 100 of task list per profile, is there a way to send the group name from clearpass to NCS prime?

     

    Thanks,

    Bharani..

     



  • 2.  RE: AAA authentication of CISCO NCS prime with Clearpass servers

    EMPLOYEE
    Posted Dec 10, 2013 09:45 AM

    We added a library for NCS in 6.2.3.  If you need it in your version, please see the attached file.  Go to Administration --> Dictionaries --> TACACS and at the top right, import this file (no password)

     

     



  • 3.  RE: AAA authentication of CISCO NCS prime with Clearpass servers

    EMPLOYEE
    Posted Dec 10, 2013 09:46 AM
      |   view attached

    Here's the file!  I forgot it.  Unzip it first...then import

    Attachment(s)

    zip
    NCS_Dictionary.xml.zip   1 KB 1 version


  • 4.  RE: AAA authentication of CISCO NCS prime with Clearpass servers

    Posted Dec 10, 2013 11:12 AM

    Hello Seth,

     

    Thanks for your reply. I have already edited this xml file as per our NCS prime's attribute task list (around 170 task list are in present in a group in NCS prime).

     

    But what I can see is that I need to manually type in all task list in clearpass profile right?

     

    Instead of doing this, is there a way to send just a group name from clearpass to NCS prime? (because that group in prime will be having all task list configured in it).

     

    Regards,

    Bharani..



  • 5.  RE: AAA authentication of CISCO NCS prime with Clearpass servers

    EMPLOYEE
    Posted Dec 11, 2013 10:31 AM

    I believe you can edit this dictionary and place those role into the categories.  Not an expert with Prime.  I believe that's how ACS does it.