Security

last person joined: 23 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Spreadsheet for rapid HPE, Aruba-S, Cisco, Juniper, and Extreme, wired 802.1x deployments

This thread has been viewed 3 times
  • 1.  Spreadsheet for rapid HPE, Aruba-S, Cisco, Juniper, and Extreme, wired 802.1x deployments

    Posted Apr 03, 2018 04:02 PM

    All,

     

    It's been a while since I posted on here and I wanted to share a way to rapdily deploy wired 802.1x across various platforms: 

     

    https://github.com/chronot1995/wired-802.1x-spreadsheet

     

    This spreadsheet that will allow you to copy and paste the relelvant RADIUS / TACACS+ / ClearPass information to deploy a uniform configuration to hundreds, even thousands, of switches.

     

    As a caveat to the above, the first place to check for any 802.1x manufacturer configurations should be the ASE website:

     

    https://ase.arubanetworks.com/

     

    I hope the spreadsheet helps - thanks!

     

    -Mike

    AMFX #5

     

    https://github.com/chronot1995/wired-802.1x-spreadsheet

     

    The spreadsheet will help deploy wired 802.1X on Cisco, Juniper, Extreme, an HPE, and Aruba-S platforms

     

    To get started, fill out the "Start Here" tab. On this tab, you can fill out the following information:

    • ClearPass / Radius Server IP addresses
    • RADIUS / TACACS+ Shared Secret 
    • RADIUS / TACACS+ Source VLAN 
    • RADIUS / TACACS+ Source IP address 
    • Interface ranges for Cisco and Juniper configurations

    The data that you enter here will populate throughout the tabs of the spreadsheet. You can then select the platform and copy and paste the relevant data into the manufacturer switch of choice.

    The "Advanced Cisco Switch Config" tab provides the following:

    • The commands for a wired Guest Portal Redirection
    • Advanced Device Sensor configuration for IOS 15+

    The "Cisco Switch Config" code has been tested on IOS 12.2.55-SE5 - IOS 15.1

    The "Juniper EX Config" code has been tested on JUNOS 12.x - JUNOS 15.x

    The "HPE Provision Config" has been tested on legacy Provision and ArubaOS-Switch 16.x images

    The "Aruba S-Series Config" was tested through Aruba S-Series code 7.4.x

    The "Extreme EXOS 15- Config" was tested on Extreme EXOS 15 and 14, hence the "-" minus sign

    The "Extreme EXOS 16+ Config" was tested on Extreme EXOS 16



  • 2.  RE: Spreadsheet for rapid HPE, Aruba-S, Cisco, Juniper, and Extreme, wired 802.1x deployments

    Posted Apr 11, 2018 03:40 AM
    Good work! (Bookmarked)


  • 3.  RE: Spreadsheet for rapid HPE, Aruba-S, Cisco, Juniper, and Extreme, wired 802.1x deployments

    Posted Apr 30, 2018 09:12 AM
    Awesome!


  • 4.  RE: Spreadsheet for rapid HPE, Aruba-S, Cisco, Juniper, and Extreme, wired 802.1x deployments

    EMPLOYEE
    Posted May 05, 2018 01:32 AM

    nice work



  • 5.  RE: Spreadsheet for rapid HPE, Aruba-S, Cisco, Juniper, and Extreme, wired 802.1x deployments

    Posted May 17, 2018 02:02 AM

    Hi, How to configure wired guest portal and OnGuard landing page with FQDN for Juniper EX switches 



  • 6.  RE: Spreadsheet for rapid HPE, Aruba-S, Cisco, Juniper, and Extreme, wired 802.1x deployments

    Posted May 18, 2018 02:05 PM

    Thanks a lot for sharing this :)



  • 7.  RE: Spreadsheet for rapid HPE, Aruba-S, Cisco, Juniper, and Extreme, wired 802.1x deployments

    Posted Oct 18, 2018 04:20 PM

    This is great work , thanks for sharing



  • 8.  RE: Spreadsheet for rapid HPE, Aruba-S, Cisco, Juniper, and Extreme, wired 802.1x deployments

    Posted Feb 16, 2019 10:03 AM

    Good Job, Thx !!



  • 9.  RE: Spreadsheet for rapid HPE, Aruba-S, Cisco, Juniper, and Extreme, wired 802.1x deployments

    Posted Feb 16, 2019 10:08 AM

    @boston1630 wrote:

    All,

     

    It's been a while since I posted on here and I wanted to share a way to rapdily deploy wired 802.1x across various platforms: 

     

    https://github.com/chronot1995/wired-802.1x-spreadsheet

     

    This spreadsheet that will allow you to copy and paste the relelvant RADIUS / TACACS+ / ClearPass information to deploy a uniform configuration to hundreds, even thousands, of switches.

     

    As a caveat to the above, the first place to check for any 802.1x manufacturer configurations should be the ASE website:

     

    https://ase.arubanetworks.com/

     

    I hope the spreadsheet helps - thanks!

     

    -Mike

    AMFX #5

     

    https://github.com/chronot1995/wired-802.1x-spreadsheet

     

    The spreadsheet will help deploy wired 802.1X on Cisco, Juniper, Extreme, an HPE, and Aruba-S platforms

     

    To get started, fill out the "Start Here" tab. On this tab, you can fill out the following information:

    • ClearPass / Radius Server IP addresses
    • RADIUS / TACACS+ Shared Secret 
    • RADIUS / TACACS+ Source VLAN 
    • RADIUS / TACACS+ Source IP address 
    • Interface ranges for Cisco and Juniper configurations

    The data that you enter here will populate throughout the tabs of the spreadsheet. You can then select the platform and copy and paste the relevant data into the manufacturer switch of choice.

    The "Advanced Cisco Switch Config" tab provides the following:

    • The commands for a wired Guest Portal Redirection
    • Advanced Device Sensor configuration for IOS 15+

    The "Cisco Switch Config" code has been tested on IOS 12.2.55-SE5 - IOS 15.1

    The "Juniper EX Config" code has been tested on JUNOS 12.x - JUNOS 15.x

    The "HPE Provision Config" has been tested on legacy Provision and ArubaOS-Switch 16.x images

    The "Aruba S-Series Config" was tested through Aruba S-Series code 7.4.x

    The "Extreme EXOS 15- Config" was tested on Extreme EXOS 15 and 14, hence the "-" minus sign

    The "Extreme EXOS 16+ Config" was tested on Extreme EXOS 16


    Did you make configs for Alcatel and Dell swichs?

    Thanks for your help



  • 10.  RE: Spreadsheet for rapid HPE, Aruba-S, Cisco, Juniper, and Extreme, wired 802.1x deployments

    Posted Apr 22, 2019 05:15 PM

    Thanks for Sharing, great work!

     



  • 11.  RE: Spreadsheet for rapid HPE, Aruba-S, Cisco, Juniper, and Extreme, wired 802.1x deployments

    Posted Jun 10, 2019 03:54 AM

    Hi, How did you tested the dot1x authentication on Juniper ex switches with JUNOS12.3R12 where RADIUS CoA port (3799) is not available i.e. dynamic-port-request.

     

    We have nearly 100 EX3300 switches with JUNOS12.3R12 version and going to deploy dot1x authentication but the version will not support "dynamic-port-request" command. Please help me with this.

     

    Thanks,

    Yugandhar.