Hi there,
I see some discussions about DUR and Secondary Roles, but I'm facing issues even with Primary roles and DUR.
I configured the switch with a ta-profile, and my radius server has cppm user and password with permissions to download roles.
I then setup a enforcement profile with type "Mobility Switch".
My interface config:
interface 1/1/3
no shutdown
description COLORLESS-PORT
no routing
vlan access 170
spanning-tree link-type point-to-point
aaa authentication port-access auth-precedence mac-auth dot1x
aaa authentication port-access allow-cdp-bpdu
aaa authentication port-access allow-lldp-bpdu
aaa authentication port-access client-limit 8
aaa authentication port-access mac-auth
cached-reauth
reauth
enable
exit
I see the request on ClearPass, and it answers with the role.
The switch log shows "2020-02-21T18:03:17.134578+00:00 f2sw01 port-accessd[3222]: Event|Unknown Event Name CERT_CHAIN_VERIFIED", meaning it is communicating with ClearPass.
But no role is applied to the interface:
# show aaa authentication port-access interface 1/1/3 client-status
Port Access Client Status Details
Client 00:xx:xx:xx:xx:xx, 000xxxxxxxx
============================
Session Details
---------------
Port : 1/1/3
Session Time : 342s
Authentication Details
----------------------
Status : mac-auth Authenticated
Auth Precedence : mac-auth - Authenticated, dot1x - Not attempted
Authorization Details
----------------------
Role :
Status : Not Ready
Client 00:xx:xx:xx:xx:xx, 000xxxxxxxx
============================
Session Details
---------------
Port : 1/1/3
Session Time : 391s
Authentication Details
----------------------
Status : mac-auth Authenticated
Auth Precedence : mac-auth - Authenticated, dot1x - Not attempted
Authorization Details
----------------------
Role :
Status : Not Ready
No errors are shown under event log.
Can someone explain what should I configure for ARUBA-CPPM-ROLE attribute under ClearPass?
I'm really starting to regret buying these half baked switches... No device fingerprinting support, no support on Clearpass, no DOCUMENTATION... Really miss my 2930f.
Thanks