Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Authenticate external tacacs to ClearPass WebUI

This thread has been viewed 16 times
  • 1.  Authenticate external tacacs to ClearPass WebUI

    Posted Jan 31, 2018 10:31 AM
      |   view attached

    In a recent presentation about CP 6.7 I’ve found a slide that says:

     

    External TACACS server for ClearPass WebUI authentication support.

     

    Unfortunately, I cannot find this option in 6.7, nor can i find anything about this in the 6.7 user guide. Does anybody know how to configure this?



  • 2.  RE: Authenticate external tacacs to ClearPass WebUI
    Best Answer

    Posted Jan 31, 2018 10:36 AM

    I found it:

    Page 548 in the user guide. 

     

    configurable under:

    Cluster wide paramaters > Tacacs

     

     



  • 3.  RE: Authenticate external tacacs to ClearPass WebUI

    Posted Mar 29, 2018 04:56 AM

     

    I'm missing the configuration part of this.

     

    For a customer, i want to use their cisco tacacs+ server and use clearpass as a tacacs+ client for remote webui login.

     

    What tacacs attrributes can i send from the server to clearpass? can i just send a Privilige Level, like: Super Administrator

     

    Do i need to configure any service in clearpass, or does it really behave as a 100% tacacs client?



  • 4.  RE: Authenticate external tacacs to ClearPass WebUI

    Posted Jul 19, 2018 12:07 PM

    Has anyone successfully configured CPPM to use an external TACACS server yet?

     

    Any idea what av_pairs CPPM is looking for?

     



  • 5.  RE: Authenticate external tacacs to ClearPass WebUI

    EMPLOYEE
    Posted Jul 19, 2018 12:16 PM

    TACACS+ does not use avpair.

     

    The cpass:HTTP service is used with the AdminPrivilege attribute.

     



  • 6.  RE: Authenticate external tacacs to ClearPass WebUI

    Posted Aug 28, 2018 08:06 AM

    Hi Tim,

     

    I am a newbee on clearpass but wat do you mean by 

    "The cpass:HTTP service is used with the AdminPrivilege attribute"

     

    is that a custom attribute on the Cisco ACS ?

    or is it a service in the Clearpass manager?

     

    regards

     

    Peter



  • 7.  RE: Authenticate external tacacs to ClearPass WebUI

    EMPLOYEE
    Posted Aug 28, 2018 08:35 AM
    Custom attribute in ACS.


  • 8.  RE: Authenticate external tacacs to ClearPass WebUI

    Posted Aug 28, 2018 10:31 AM

    Hi Tim thanks for your response.

     

    but  which attribute do i need?2018-08-28_16-28-02.png



  • 9.  RE: Authenticate external tacacs to ClearPass WebUI

    EMPLOYEE
    Posted Aug 30, 2018 08:09 AM

    Hi Peter,

     

    You need to configure attribiute and value as,

    Attribute = AdminPrivilege

    Value = Super Administrator 

     

    Other admin privileges in ClearPass.

    admin_priv.jpg

     

    Note: As mentioned by TIm, the service type should be cpass:HTTP, i.e. service=cpass and protocol=http when you create TACACS+ service/customer attributes in ACS.