Wired Intelligent Edge

last person joined: 19 hours ago 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

Aruba Switch EST Enrollment to ClearPass

This thread has been viewed 26 times
  • 1.  Aruba Switch EST Enrollment to ClearPass

    Posted Sep 25, 2019 12:20 PM
      |   view attached

    Has anyone gotten EST enrollment working from an Aruba Switch (e.g. 3810M) to ClearPass Onboard? I have the CA configured correctly as a registration authority (RA) and it is valid in Onboard. However, I am unable to get the switch to enroll due to SSL connection error. I have a ta-profile for the upstream intermediate CA that the RA is connected to loaded on the switch. I can't help but notice that the URL that ClearPass says to use for EST is using port 9 instead of 443. Thoughts? Just wondering what I am missing. 



  • 2.  RE: Aruba Switch EST Enrollment to ClearPass

    Posted Sep 27, 2019 10:19 AM

    Shouldn't that be /9 instead of :9, is that a GUI display issue?  ( I think the /9 is just the 9th Ca you have setup, it just increments each time)

     

    If it was a port, it would be straight after your hostname, before the folder structure.



  • 3.  RE: Aruba Switch EST Enrollment to ClearPass
    Best Answer

    Posted Sep 27, 2019 01:57 PM

    Good call on that. Yeah, that has to be a GUI bug.

     

    Regardless, can't seem to get it to work. TAC call it is



  • 4.  RE: Aruba Switch EST Enrollment to ClearPass

    Posted Sep 27, 2019 02:04 PM

    I did notice that in Onboard you have the option for configuring the EST authentication for either shared secret or HTTP Basic/Digest. The switch does not seem to have shared secret as an option. Is there a place to configure the HTTP auth on the switch?



  • 5.  RE: Aruba Switch EST Enrollment to ClearPass

    Posted Sep 27, 2019 02:25 PM

    Nevermind. I found it. The user has to be an active guest account for HTTP auth.