Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

TACACS+ and ACS v4

This thread has been viewed 0 times
  • 1.  TACACS+ and ACS v4

    Posted Mar 27, 2014 04:15 PM

    I can configure TACASC+ in ACS v4?

    Currently I have it configured, but it does not works.



  • 2.  RE: TACACS+ and ACS v4

    EMPLOYEE
    Posted Mar 27, 2014 04:18 PM

    Is this a question or comment. 

     

    You will need to provide a lot more information.

     

    Device

     

    Name

    Firmware

    errors in device

     

    CPPM 

     

    Version

    screen shots of errors in access tracker

     

    ETC. 

     

    TACACS 

     

    Commands

     

    ETC....



  • 3.  RE: TACACS+ and ACS v4

    Posted Mar 28, 2014 04:36 AM
      |   view attached

    The conf in Controller:

     

    aaa server-group "TACACS-SVR-GROUP"
    auth-server TACACS-SERVER-A
    !
    aaa authentication-server tacacs "TACACS-SERVER-A"
    host "X.X.X.X"
    key XXXXXXXXXXXXX
    tcp-port 4949
    session-authorization
    !
    aaa authentication mgmt
    server-group "TACACS-SVR-GROUP"
    enable
    !
    aaa tacacs-accounting server-group TACACS-SVR-GROUP mode enable command all

     

    The error in ACS:

     

     

    service denied - service=aruba protocol=common



  • 4.  RE: TACACS+ and ACS v4

    EMPLOYEE
    Posted Mar 28, 2014 03:12 PM

    If you're stuck with TACACS+, a valid alternative might be using RADIUS. You can download Aruba VSAs for ACS from this link:

     

    http://support.arubanetworks.com/ToolsResources/tabid/76/DMXModule/514/EntryId/115/Default.aspx

     

    Regards



  • 5.  RE: TACACS+ and ACS v4

    Posted Apr 01, 2014 10:08 AM
      |   view attached

    What add value?



  • 6.  RE: TACACS+ and ACS v4
    Best Answer

    EMPLOYEE
    Posted Apr 02, 2014 04:54 PM

    If you want administration access you need to pass back to the controller the following: Aruba-Admin-Role = root