Wired Intelligent Edge (Campus Switching and Routing)

Reply
Highlighted
Regular Contributor II

Aruba 2930F Tunneled Port Clearpass Roles

Hi,

 

I´ve set up a 2930F Switch for testing port tunneling. 

The Switch has firmware WC.16.05.0004.

The Controller has code verson 6.5.4.3 on it, for authentication I use Clearpass 6.7.

The tunnel comes up and the authentication works fine, but the controller ignors the radius response attriubte send from clearpass.

The controller set always its default role.

 

Have anyone an idea where the problem is?

 

Thanks

 

1.png2018-03-13 15_38_00-Monitoring.png

3.png


Accepted Solutions
Highlighted
Moderator

Re: Aruba 2930F Tunneled Port Clearpass Roles

You should not be using Enforce Machine Authentication when using ClearPass. Disable that.

| Tim Cappalli | Aruba Security | @timcappalli | timcappalli.me |

NOTE: Answers and views expressed by me on this forum are my own and not necessarily the position of Aruba or Hewlett Packard Enterprise.

View solution in original post


All Replies
Highlighted
Moderator

Re: Aruba 2930F Tunneled Port Clearpass Roles

Does that role exist on the controller?

| Tim Cappalli | Aruba Security | @timcappalli | timcappalli.me |

NOTE: Answers and views expressed by me on this forum are my own and not necessarily the position of Aruba or Hewlett Packard Enterprise.
Highlighted
Regular Contributor II

Re: Aruba 2930F Tunneled Port Clearpass Roles

yes

4.png

Highlighted
Moderator

Re: Aruba 2930F Tunneled Port Clearpass Roles

You should not be using Enforce Machine Authentication when using ClearPass. Disable that.

| Tim Cappalli | Aruba Security | @timcappalli | timcappalli.me |

NOTE: Answers and views expressed by me on this forum are my own and not necessarily the position of Aruba or Hewlett Packard Enterprise.

View solution in original post

Highlighted
Regular Contributor II

Re: Aruba 2930F Tunneled Port Clearpass Roles

Thanks, now it works.

Highlighted
Anonymous
Not applicable

Re: Aruba 2930F Tunneled Port Clearpass Roles

@Leon123, what licensing did you need to use for the tunnelled port?

Highlighted
Moderator

Re: Aruba 2930F Tunneled Port Clearpass Roles

Per-Port consumes 1 of each controller licenses for each switch stack.


| Tim Cappalli | Aruba Security | @timcappalli | timcappalli.me |

NOTE: Answers and views expressed by me on this forum are my own and not necessarily the position of Aruba or Hewlett Packard Enterprise.