Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

TACACS on CPPM for Network Device (CIsco) Authentication.

This thread has been viewed 1 times
  • 1.  TACACS on CPPM for Network Device (CIsco) Authentication.

    Posted Jan 28, 2019 09:07 AM

    Hey all, I struggled for a day trying to figure out the cause of an error and I just can't seem to fix it.  The TACACS config i'm using came from the recipes section and it works in a different instance of CPPM i'm running in a different enviroment. here is a screenshot of the error. I'm running 6.7.8.109113

    Error.png

    Below are screenshots of my configuration.  Any help would be greatly appreciated. 

    en_policy.png

     

    en_profile.png

     

    services.png

     



  • 2.  RE: TACACS on CPPM for Network Device (CIsco) Authentication.

    EMPLOYEE
    Posted Jan 29, 2019 05:00 AM

    Are you sure the authentication ends in the profile that you created?

     

    Two suggestions to verify that:

    1) Change the default role in the service to your RW admin profile. If it works then, there is an issue with the enforcement policy (does not match).

    2) Change the 'Unmatched commands' to permitted.

     

    Here is an example that should work, and the only difference that I see is the 'Unmatched commands' (and a timeout):

    Screen Shot 2019-01-29 at 10.58.09 AM.png



  • 3.  RE: TACACS on CPPM for Network Device (CIsco) Authentication.

    Posted Jan 29, 2019 09:08 AM

    Herman, Thanks for your response.  I tried both of your recommandations and neither work.  I decided to completely remove the TACACS config and start from scratch.  I followed your video on Youtube and everything works now.  Maybe something I missed the first time around?  Either way thanks for your videos and thanks for your response. 



  • 4.  RE: TACACS on CPPM for Network Device (CIsco) Authentication.

    Posted Jan 11, 2020 02:34 PM

    This fixed my problem. it wasn't listed in the guide.