Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Panorama Integration - authentication error

This thread has been viewed 3 times
  • 1.  Clearpass Panorama Integration - authentication error

    Posted Oct 21, 2014 08:51 PM
    Hi,
     
    I've been following the technote but not seeing users appear in Panorama.
     
    The Clearpass log shows it is trying but is getting a permissions error from PA:
     
    2014-10-21 15:26:46,544 DEBUG  root             pactrlmonitprofile Read response={<response status = 'error' code = '403'><result><msg>User not authorized to perform this operation.</msg></result></response>
     
    But our user has the right permissions - User-ID agent under XML API. 
     
    Unfortunately none of the troubleshooting commands in the technote seem to work on Panorama. Can anyone suggest how to troubleshoot this further?
     
    regards,
     
    B

     



  • 2.  RE: Clearpass Panorama Integration - authentication error
    Best Answer

    Posted Oct 21, 2014 10:14 PM

    What version of PANOS?   There was a specific fix for this very issue; but it was back in version 5.0.5:

     

    49114Customer was unable to add User-IP Mapping to a firewall using the API and the following error message was displayed : “User not authorized to perform this operation”. This problem occurred with an admin account created with the “User-ID Agent” privilege only. The issue has been resolved with this release.

     

     

    Also, did you input all the PAN endpiont serial numbers in the Palo Alto Networks Panorama Endpoint Context Server configuration?



  • 3.  RE: Clearpass Panorama Integration - authentication error

    Posted Oct 21, 2014 10:20 PM
      |   view attached

    Hi,

     

    Software is 6.0.5. We have entered all the serial numbers and the Panorama one too just in case.

     

    Current perms attached, the user has most perms under web as well.

     

    The user is under the Panorama Admins not Device Admins, would that make a difference?

     

     



  • 4.  RE: Clearpass Panorama Integration - authentication error

    Posted Oct 23, 2014 06:08 PM

    Anyone have experience with this?



  • 5.  RE: Clearpass Panorama Integration - authentication error

    Posted Jan 22, 2015 03:38 AM

    Issue still unresolved...

     

    No usernames appearing and no logs/errors in either PA or CP.

     

    Enforcement profiles shows it is working.



  • 6.  RE: Clearpass Panorama Integration - authentication error

    Posted Jan 26, 2015 11:19 PM

    Let me do some mock and i'll get back to you.

     

     

     



  • 7.  RE: Clearpass Panorama Integration - authentication error

    Posted Jan 28, 2015 04:07 PM

    have you opened a TAC ticket?



  • 8.  RE: Clearpass Panorama Integration - authentication error

    Posted Jan 28, 2015 08:23 PM

    Was working with my local Aruba tech on this, but time to open one I think. I did have a case open with Palo Alto but no result. Also I didn't manage to get any information on how to verify the push is working from the PA end. It seems the Collect Logs is the only mechanism. 

     

    I have just upgraded Clearpass to 6.3.6 and we are now seeing some usernames in Panorama, but not all clients IPs have one. Would like to figure out why it doesn't occur for all users.

     

    The second issue is the Panorama integration doesn't seem to work at all, so my workaround is to push to all firewall appliances instead (i.e. one enforcement profile with a rule for each appliance in the network).

    The downside of this is we are pushing to firewalls that don't even know about a particular IP. Might this be causing push failures since 8 firewalls have to updated for every login event?

     

    So I have just refined this a bit at the expense of complicating the Enforcement Policy. Now we check NAS IP address and only push to the relevant firewalls for that NAS's location. First indications are this hasn't made the push any more reliable.

     

    Worth noting if I manually create and post the XML it works every time :)

     

     



  • 9.  RE: Clearpass Panorama Integration - authentication error

    Posted Feb 28, 2015 01:59 AM

    Was curious if you had any resolution on this issue. We just received a PA5060 to demo, and I'm seeing the same error you are despite following the technotes/having their professional services guy walk us through the integration.

     

    2015-02-28 01:09:06,077 INFO root pactrlmonitprofile PA_Panorama_Username_Transform=none
    2015-02-28 01:09:06,077 DEBUG root pactrlmonitprofile Sending UID mapping to Palo Alto device
    2015-02-28 01:09:06,078 WARNING root pactrlmonitprofile Not sending userid object for padevice=172.29.40.252 as the data or auth_token is empty
    2015-02-28 01:09:06,078 DEBUG root pactrlmonitprofile Sending userid object for padevice=172.29.40.252
    2015-02-28 01:09:06,246 DEBUG root pactrlmonitprofile Read response={<response status = 'error' code = '403'><result><msg>User not authorized to perform this operation.</msg></result></response>} from padevice

     

    Our ClearPass install is on 6.4.4 and the PAN-OS is 6.1.2 so neither are particularly old. I'll be opening a TAC ticket of my own shortly but figured it wouldn't hurt to ask if you had found a solution for this yet. :)



  • 10.  RE: Clearpass Panorama Integration - authentication error

    MVP GURU
    Posted Oct 21, 2015 04:12 AM

    For information, i have the same error with a customer and the problem coming from password complexity on PAN...

     

    There is a tech note on Palo Alto Web Site (Need a account or use Google Cache...)

    http://webcache.googleusercontent.com/search?q=cache:UgTTp3XX5csJ:https://live.paloaltonetworks.com/t5/tkb/articleprintpage/tkb-id/TechnologiesSDKsArticles/article-id/382+&cd=3&hl=fr&ct=clnk&gl=fr