Wired Intelligent Edge

last person joined: yesterday 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

TACACS with Cisco ISE and ArubaOS-Switch

This thread has been viewed 21 times
  • 1.  TACACS with Cisco ISE and ArubaOS-Switch

    EMPLOYEE
    Posted Mar 20, 2019 01:40 PM
      |   view attached

    Hello everyone,

     

    This guide below is how to set up TACACS with ArubaOS-Switch using Cisco ISE.  

     

     

     

    Was missing Some Commands from the Document 

    "aaa authentication login privilege-mode"

    "aaa authorization commands tacacs"

     

    Attachment(s)



  • 2.  RE: TACACS with Cisco ISE and ArubaOS-Switch

    Posted Oct 02, 2019 10:38 AM

    Do you have guide for Aruba Device Management via Cisco ISE?



  • 3.  RE: TACACS with Cisco ISE and ArubaOS-Switch

    MVP GURU
    Posted Oct 02, 2019 03:09 PM

    @capricorn80 wrote:

    Do you have guide to Aruba Deve Management via Cisco ISE?


    What do you need ?



  • 4.  RE: TACACS with Cisco ISE and ArubaOS-Switch

    Posted Oct 02, 2019 03:13 PM
    I am trying to setup Aruba 2540 and 2930 ssh admin login via Cisco ISE using radius. Also web login if possible.

    Get Outlook for iOS


  • 5.  RE: TACACS with Cisco ISE and ArubaOS-Switch

    MVP GURU
    Posted Oct 03, 2019 12:16 PM

    it is the same config... but replace TACACS by RADIUS ;-)



  • 6.  RE: TACACS with Cisco ISE and ArubaOS-Switch

    Posted Oct 03, 2019 01:47 PM

    Thanks but I dont have Tacas option like like Jr_admin Profile.

    I have created Result condition as below but it doesnt work.

     

    Aruba: Aruba-Priv-Admin-Role = root

    Attributes Details

    Access Type = ACCESS_ACCEPT
    Aruba-Admin-Role = root

     

     



  • 7.  RE: TACACS with Cisco ISE and ArubaOS-Switch

    MVP GURU
    Posted Oct 03, 2019 02:37 PM

    it is for Aruba Switch ?

    you need to add push like a Cisco switch shell-privilege



  • 8.  RE: TACACS with Cisco ISE and ArubaOS-Switch

    Posted Oct 03, 2019 02:45 PM

    Yes its for Aruba Switch.

     

    Cisco priv works like this.

     

    Access Type = ACCESS_ACCEPT
    cisco-av-pair = shell:priv-M=15

     

    Tried with HP radius option.

    Access Type = ACCESS_ACCEPT
    HP-Privilege-Level = 15

     

    did not work.



  • 9.  RE: TACACS with Cisco ISE and ArubaOS-Switch

    MVP GURU
    Posted Oct 04, 2019 09:02 AM

    use cisco-av-pair for HP Switch



  • 10.  RE: TACACS with Cisco ISE and ArubaOS-Switch

    Posted Oct 04, 2019 09:29 AM

    Thanks but I am getting it.

     

    The Cisco AV pair for shell access is:

    cisco-av-pair = shell:priv-M=15

     

    I have tried it but it didnt work.

     

    Can you please tell me the exact format?





  • 11.  RE: TACACS with Cisco ISE and ArubaOS-Switch



  • 12.  RE: TACACS with Cisco ISE and ArubaOS-Switch

    Posted Oct 04, 2019 10:18 AM

    No I dont see it.

     

    https://community.arubanetworks.com/t5/Security/ArubaOS-Admin-Authentication-with-Microsoft-NPS/td-p/433832

     

    This article is similar and the person is using attribute 4 with string root.

     

    I tried the same but it doesnt work.

     

    Access Type = ACCESS_ACCEPT
    Aruba-Admin-Role = root



  • 13.  RE: TACACS with Cisco ISE and ArubaOS-Switch

    MVP GURU
    Posted Oct 07, 2019 01:40 PM

    It is for RADIUS and Aruba(OS) Controller...



  • 14.  RE: TACACS with Cisco ISE and ArubaOS-Switch

    Posted Oct 07, 2019 03:03 PM

    Ok thanks.

    Any doc where I can find the exact value for Aruba switch shell?



  • 15.  RE: TACACS with Cisco ISE and ArubaOS-Switch
    Best Answer

    Posted Oct 06, 2020 12:02 PM

    Finally I tested it again and is able to fix this.

    So I used Radius and then following settings on ISE to login.

    Network Device Profile Cisco

    Access Type = ACCESS_ACCEPT
    Service-Type = 6