Security

last person joined: 23 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass TACACS - Authentication fail

This thread has been viewed 15 times
  • 1.  Clearpass TACACS - Authentication fail

    Posted Oct 08, 2014 03:44 PM

    Hi Guys,

     

    I'm using the CPPM as a TCACS Server, authenticanting some different switches models .

    I'm having a problem specifically with an HP (H3C) switch. When I try to access this switch with username and password that is registered in CPPM internal base, I receive the information from CPPM that the autehntication was accepted, but the switch reject the access.

     

    I have no problem with the others switches ( Ciscco and Dell).

     

    Is there something that I need to configure in the CPPM specically for HP (H3C) switches?

     

    Thanks i advance.

     

    Leandro Surcin



  • 2.  RE: Clearpass TACACS - Authentication fail

    EMPLOYEE
    Posted Oct 08, 2014 03:51 PM
    Youneed to send back a privilege level of 15. Create a new enforcement profile and add it to your policy.


  • 3.  RE: Clearpass TACACS - Authentication fail

    EMPLOYEE
    Posted Oct 08, 2014 04:05 PM

    HP ProCurve config:

     

    aaa authentication login privilege-mode
    aaa authentication ssh login tacacs local
    aaa authentication ssh enable tacacs local
    tacacs-server host 10.100.60.80 key Pr0Curve

     

    ClearPass:

     

    Enforcement profile:

    tacacs-hp-procurve-enfprofile.JPG

     

     

     

    Enforcement policy:

     

    tacacs-hp-procurve-enfpolicy.JPG



  • 4.  RE: Clearpass TACACS - Authentication fail

    Posted Oct 20, 2014 03:34 PM

    Hi.

     

    Its an HP 5120 switch model from H3C and I already configured the enforcement profile privilege level 15.

     

    Do you have some other advice?

     

    Tks.



  • 5.  RE: Clearpass TACACS - Authentication fail
    Best Answer

    Posted Oct 20, 2014 04:28 PM

    Have you set super password?

     

    [CS01]super password level 3 cipher ?
      STRING<1-53>  Ciphertext password string
    [CS01]super password level 3 cipher yoursecretkey

     then after you authenticate at level 0, type "super" to get to level 3

    <CS01>super
    Please input the password to change the privilege level. Press CTRL_C to abort.
     Password:
    User privilege level is 3, and only those commands can be used
    whose level is equal or less than this.
    Privilege note: 0-VISIT, 1-MONITOR, 2-SYSTEM, 3-MANAGE

     



  • 6.  RE: Clearpass TACACS - Authentication fail

    Posted Oct 20, 2014 05:34 PM

    Hi.

     

    Its an HP 5120 switch model from H3C and I already configured the enforcement profile privilege level 15.

     

    Do you have some other advice?

     

    Tks.



  • 7.  RE: Clearpass TACACS - Authentication fail

    EMPLOYEE
    Posted Feb 12, 2018 06:03 AM

    Did you ever get to the bottom of this?