Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM TACACS+ for autnenticating Riverbed Steelhead admins

This thread has been viewed 9 times
  • 1.  CPPM TACACS+ for autnenticating Riverbed Steelhead admins

    Posted Dec 12, 2014 10:59 AM

    All,

     

    I'm trying to use CPPM to control admin access to my Riverbed appliances.

    I keep getting the following alert in the access tracker: Tacacs service=rbt-exec:unknown not enabled

     

    CPPM error.PNG

     

    I have however imported a TACAS service called rbt-exec:unknown in the TACACS+ Services Dictionaries.

     

    TACAS_Service.PNG

     

    I have restarted the TACAS service on both my CPPM's (they are clustered).

    I have followed this how-to: http://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/How-to-authenticate-Riverbed-admin-users-against-ClearPass-over/ta-p/192945

    All help and suggestions are welcome!

     

     

    Thanks

     

    Leo

     



  • 2.  RE: CPPM TACACS+ for autnenticating Riverbed Steelhead admins
    Best Answer

    Posted Jan 02, 2015 09:33 AM

    this is fixed now.



  • 3.  RE: CPPM TACACS+ for autnenticating Riverbed Steelhead admins

    Posted Jan 02, 2015 11:29 AM

    could you explain what you did leo? it might help others with the same question.



  • 4.  RE: CPPM TACACS+ for autnenticating Riverbed Steelhead admins
    Best Answer

    Posted Jan 05, 2015 03:43 AM

    I missed one setting on the Riverbeds.

     

    You must set the authorisation policy on the riverbed to remote only. I missed that...

     

    The how-to showed the setting on a screenshot, but did not describe the action to be taken....

     

     

    Regards,

     

    Leo

     

     

     



  • 5.  RE: CPPM TACACS+ for autnenticating Riverbed Steelhead admins

    Posted Apr 16, 2015 09:45 AM

    What vendorname do you set for your Riverbed devices?





  • 6.  RE: CPPM TACACS+ for autnenticating Riverbed Steelhead admins

    Posted Jun 23, 2015 11:50 AM

    Has anyone tried this using the "monitor" role (read-only) within Riverbed? This works just fine using the admin role, but suppose someone (me) needed to define read-only access to Riverbed appliances, using CPPM? Haven't gotten this to work ... it only shows the following in my Authorization failure access tracker window:

     

    aruba-cppm-rvbd-monitor-fail.jpg



  • 7.  RE: CPPM TACACS+ for autnenticating Riverbed Steelhead admins

    Posted Jun 24, 2015 05:08 AM

    Please post a screenshot of your enforcement policy in clearpass