Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Balance TACACS+ request with CPPM and F5

This thread has been viewed 20 times
  • 1.  Balance TACACS+ request with CPPM and F5

    Posted Jan 23, 2020 08:28 AM

    Hi.

     

    Currently I'm using the F5 to balance radius request between 5 subscribers, this is working fine.

     

    I would like to do the same with TACACS+.

    Are there any guide to configure it?



  • 2.  RE: Balance TACACS+ request with CPPM and F5



  • 3.  RE: Balance TACACS+ request with CPPM and F5

    Posted Jan 23, 2020 12:36 PM

    Hello, yes, I want to do this (Load balancing TACACS authentication).

     

    But this link doesn't has the steps to configure in Clearpass.

    I would like to know if there are a document like we have for RADIUS.

     



  • 4.  RE: Balance TACACS+ request with CPPM and F5

    Posted Jan 29, 2020 09:57 AM

    Hello, anyone configured load balance using F5 for Tacacs request?



  • 5.  RE: Balance TACACS+ request with CPPM and F5

    EMPLOYEE
    Posted Jan 29, 2020 11:44 AM

    Hi,

     

    As per the solution given by the above link, we have to do changes in F5 not in ClearPass. From ClearPass end we just need to have Authentication and Authorization request on the same server,

     

    Solution

    As F5 was load balancing the requests, we can ensure the TACACS auth and TACACS authorization request hits the same node by enabling session persistence on F5 load balancer.

     



  • 6.  RE: Balance TACACS+ request with CPPM and F5

    Posted Jan 30, 2020 02:20 PM

    Hi Vikran, I'm not with the same issue, the F5 is already configured with session persistence. 

     

    I would like a configuration guide on how to configure Clearpass to load balance TACACS+ requests from Network Devices using F5 VIP

     

    NAD -> F5 -> CPPM

     

    I already create a TACACS Enforcement service, but is not working. I guess I'm missing something in the service config at Clearpass. 

    For Radius load balance using F5 it's working.

     



  • 7.  RE: Balance TACACS+ request with CPPM and F5



  • 8.  RE: Balance TACACS+ request with CPPM and F5

    Posted Feb 03, 2020 09:41 AM

    This guide is to configure F5 to access using TACACS.

     

    I would like a configuration guide on how to configure Clearpass to load balance TACACS+ requests from Network Devices using F5 VIP



  • 9.  RE: Balance TACACS+ request with CPPM and F5

    EMPLOYEE
    Posted Feb 04, 2020 03:06 AM

    Hi , 

     

    I believe there is no as such guide, you can use Virtual IP on ClearPass cluster to load balance the TACACS requests coming to ClearPass.