Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

User Role not downloading

This thread has been viewed 15 times
  • 1.  User Role not downloading

    Posted Jun 12, 2019 01:05 AM

    i have connected a new switch(its a 24 port switch) to my network and its been 4 days and no user roles have been downloaded.

    the switch has been added to clearpass.

    no error logs on the switch relating to why user roles are not downloading.

    user role download is set to enable

    running clearpass 6.7

     

    what and where do i need to check on why its not downloading the user role



  • 2.  RE: User Role not downloading

    EMPLOYEE
    Posted Jun 12, 2019 01:17 AM
    User roles are downloaded as devices authenticate and require the role.


  • 3.  RE: User Role not downloading

    Posted Jun 12, 2019 01:19 AM

    is there a way to check if the device has been authenticated?

    what can i check?

    surely it shouldnt take 4-5 days to authenticate



  • 4.  RE: User Role not downloading

    EMPLOYEE
    Posted Jun 12, 2019 01:21 AM
    Access Tracker.


  • 5.  RE: User Role not downloading

    Posted Jun 12, 2019 01:25 AM

    can you be bit more descriptive.

    am i checking if the switch is authenticating?

     

    is there anything in the switch side i need to check to make sure if all the config is good or not



  • 6.  RE: User Role not downloading

    EMPLOYEE
    Posted Jun 17, 2019 08:11 AM

    Did you follow the Wired Policy Enforcement Guide? Or this video on the Airheads Broadcasting Channel?

     

    Some basic things to check:

    - Does the port do authentication at all? show port access clients / show port access clients <port-number> detailed 

    - Is the switch local clock synchronized? show ntp status

    - Does the switch get the ClearPass root CA as trust anchor? show crypto pki ta-profile

    - Did you configure the switch with the ClearPass Downloadable Role admin credentials? 

    radius-server cppm.arubalab.com identity aos-switch-dur key password-here

    - Did you enable the role-download (you mentioned yes!):  

    aaa authorization user-role enable download

    - Did you enable role based on the switch? 

    aaa authorization user-role enable

     

     



  • 7.  RE: User Role not downloading

    Posted Jun 17, 2019 06:50 PM

    appreciate your detailed questions.

    to answer them i found that i did not have the cert installed and as soon as i installed it downlaoded 1 of 2 user roles.

    i am still waiting for the switch to dwonload the 2nd role.

     

    i would imagine this would answer all of your questions.

     i cant find anywhere in the logs in terms of why its not downloading the 2nd role. this switch is a replica of another switch which has downloaded the all other roles



  • 8.  RE: User Role not downloading

    Posted Jun 18, 2019 06:03 AM

    What version of firmweare are you runnig on the switch. If you use 16.8.3  and configure your radius servers to be clearpass servers then the cert download will happen automagically.

     

     



  • 9.  RE: User Role not downloading

    Posted Jun 18, 2019 06:33 PM

    ning 16.8.1