Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

TACACS+ Authorization

This thread has been viewed 25 times
  • 1.  TACACS+ Authorization

    Posted Apr 18, 2017 06:07 PM

    Hi guys,

     

    We have a CPPM running 6.6.5.93747.

    I've created a service to Authenticate and Authorize admin user to login in Palo Alto Networks firewall using TACACS+. The Authenticate step are ok... The user can login on the Firewall using CPPM as TACACS+ Server. The problem is in Authorization. I cannot enforce admin group privilege. 

     

    The PA firewall sent some parameter on authentication proccess: 

     

    Authorization request sent with priv_lvl=1 user=tacacsuser service=PaloAlto protocol=firewall

     

    I've attached Access Tracker "Authorizations" and "Alerts" screens with the errors.

     

    I need sent back the attribute "PaloAlto-Admin-Role" with name of the user profile.

     

    Authorization support using TACACS+ are new in PA firewall. It was inclued in the latest major version released a month ago.. So, I don't know if someone else will have the same problem as me. Therefore, if you have other kind of scenario that I can copy, I appreciate.

     

    Thank you.

     

    Paulo R.



  • 2.  RE: TACACS+ Authorization

    EMPLOYEE
    Posted Apr 18, 2017 06:12 PM
    What version of PANOS are you running?


  • 3.  RE: TACACS+ Authorization

    Posted Apr 18, 2017 06:14 PM

    Hi Tim,

     

    PANOS 8.0.1.

     

    Here a PA Doc of a configuretion in Cisco ACS using Authorization profiles: 

    https://live.paloaltonetworks.com/t5/Configuration-Articles/Palo-Alto-Management-Access-through-TACACS/ta-p/149144



  • 4.  RE: TACACS+ Authorization
    Best Answer

    Posted Apr 18, 2017 06:23 PM

    Hi..

     

    I found the issue.. As PANOS sent "service=PaloAlto protocol=firewall " in Authorization, we need create a TACACS+ Services called PaloAlto:firewall with "PaloAlto-Admin-Role" string.

     

    Thanks 



  • 5.  RE: TACACS+ Authorization

    EMPLOYEE
    Posted Apr 18, 2017 06:40 PM
      |   view attached

    Yes, that's correct. Attached is the TACACS+ dictionary.

     

    Attachment(s)



  • 6.  RE: TACACS+ Authorization

    Posted Mar 27, 2018 04:47 PM

    I seem to be failing the authorization part too (Authentications show passed, but Firewall denies me access)

     

    I added the dictionary listed in this post and dumped my SHELL profile for a PaloAlto:Firewall version that had the PaloAlto-Admin-Role included, and return "superuser" , but man, can't figure out why its rejected.

    PANOS 8.0.7, 6.7.2 Clearpass