Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Access tacacs+ in clearpass

This thread has been viewed 1 times
  • 1.  Access tacacs+ in clearpass

    Posted Apr 04, 2014 02:23 AM

    I can set access tacacs in clearpass?

    as configured?



  • 2.  RE: Access tacacs+ in clearpass

    Posted Apr 04, 2014 03:46 AM

    Can you expand upon your question please?

     

    It isn't clear what you're trying to achieve. Can you be more specific?

     



  • 3.  RE: Access tacacs+ in clearpass

    Posted Apr 04, 2014 06:37 PM
    i can configure tacacs access for ClearPass?


  • 4.  RE: Access tacacs+ in clearpass

    EMPLOYEE
    Posted Apr 04, 2014 07:33 PM
    Yes


  • 5.  RE: Access tacacs+ in clearpass

    Posted Apr 04, 2014 07:54 PM
    how configure in ClearPass? some guide?


  • 6.  RE: Access tacacs+ in clearpass
    Best Answer



  • 7.  RE: Access tacacs+ in clearpass

    Posted Apr 05, 2014 06:49 AM

    I do not want ClearPass of tacacs server. I want to configure tacacs access (ACS) by ClearPass



  • 8.  RE: Access tacacs+ in clearpass

    Posted Apr 08, 2014 05:11 AM

    I think you're asking if you can set administrative logins into Clearpass to be authenticated via an external TACACs server correct?

     

    If so, no I don't believe there's a way to do that (unless one of the other guys knows differently).

     

    What you could try, is validating administrative connections into Clearpass via a RADIUS proxy. Cisco ACS (if that's what you're using) acts as a standard RADIUS too (unless you've turned it off), so that might work. Never tried it. If I was going to, I'd...

     

    Setup a proxy...

     

    Configuration > Network > Proxy Target

     

    Then define a service that uses the proxy, but otherwise looks like the "Policy Manager Admin Network Login Service" service.

     

    This might break it if it didn't work, so try it in a lab first.