Wired Intelligent Edge

last person joined: yesterday 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

What are the new AAA security features introduced in ArubaOS-Switch Version 16.05?

This thread has been viewed 2 times
  • 1.  What are the new AAA security features introduced in ArubaOS-Switch Version 16.05?

    EMPLOYEE
    Posted Apr 04, 2018 01:56 PM

    There are four AAA security features introduced in ArubaOS-Switch Version 16.05.

     

    Open Authentication: Open Authentication (OpenAuth) Role allows a device to obtain network access before that particular device is placed under authentication process.

     

    Critical Authentication: This feature enhancement is to support a “Critical VLAN” concept, where in a remote authentication scenario such as MAC-Auth or 802.1X starts for a client, but the authentication server is not reachable then, the client will be placed in a “Critical VLAN”.

     

    Per-Port Initial Role: ArubaOS-Switches supports initial role where the clients that are rejected by radius server or clients that fails authentication due to radius unreachability will be applied with this initial role.  Initial role can be tweaked to provide limited access to download supplicant or be used for Wired Guest access solution.

     

    Mac-Pinning: With MAC Pinning feature enabled, LMA/MAC-based authenticated clients will remain authenticated in the switch even during the client’s inactivity throughout the log-off period.

     

    I have attached these four feature guides to this post which includes in-depth explanation with configuration examples.

     

    Thank You,

    Attachment(s)

    docx
    MAC_Pinning.docx   454 KB 1 version
    docx
    Per-Port_Initial_Role.docx   474 KB 1 version


  • 2.  RE: What are the new AAA security features introduced in ArubaOS-Switch Version 16.05?

    Posted Jun 20, 2018 09:39 AM

    Ciao Priyank,

    and thank for sharing those informations.

    I think Critical VLAN is a cool feature helps to implement 802.1x in a small remote office. Do you know if it will be support 25x0 as well?

     

    Thanks



  • 3.  RE: What are the new AAA security features introduced in ArubaOS-Switch Version 16.05?

    EMPLOYEE
    Posted Jun 20, 2018 01:27 PM

    Hello,

     

    The Critical Authentication Role is not supported on Aruba 2500 Series Switch.

     

    Thank You,



  • 4.  RE: What are the new AAA security features introduced in ArubaOS-Switch Version 16.05?

    Posted Sep 07, 2018 04:58 AM

    Question on MAC-pinning.

     

    What would happen if I enable MAC-pinning on all switchports that are controlled by Clearpass for both 802.1X and MAC-auth? So both aaa port-access authenticator and aaa port-access mac-based enabled on all switchports?

     

    I'm in a project that went live 3 weeks ago anf we are experiencing the  non-chatty device syndrome. Unfortunately these devices still get moved within the building so enabling MAC-pinning on specific ports is not an option. The dynamic vlan configuration feature was a Clearpass selling point so breaking this is a last resort.

     

    I currently have set the logoff-period to 300000 to solve this problem but the MAC-pinning feature looks like a better solution

     

    thanks

    Erik



  • 5.  RE: What are the new AAA security features introduced in ArubaOS-Switch Version 16.05?

    Posted Aug 19, 2019 03:34 AM

    Anything new on the mac pinning? iv got alot of "legacy" things that are moved around so mac pinning on a port is not a solution, can clearpass send mac pinning on a port? so i just configure it on my device and clearpass sends the mac pinning to the switch?



  • 6.  RE: What are the new AAA security features introduced in ArubaOS-Switch Version 16.05?

    EMPLOYEE
    Posted Aug 19, 2019 04:32 AM

    Yes, this is supported using logoff-period under a user-role since ArubaOS-switch version 16.06 with 2930F switch series and higher. A vlaue of 0 is infinity like mac-pinning. 

     

    http://h22208.www2.hpe.com/eginfolib/Aruba/16.09/5200-5908/index.html#GUID-7B8ECA6C-9966-49CA-A823-202A274E851C.html



  • 7.  RE: What are the new AAA security features introduced in ArubaOS-Switch Version 16.05?

    Posted Aug 19, 2019 06:14 AM

    Nice i'll try that, and if we have some cisco switch is there a way to do that also? we are in a process of changing our 1000 cisco switch to aruba 2930f but its gonna take some time



  • 8.  RE: What are the new AAA security features introduced in ArubaOS-Switch Version 16.05?

    Posted Aug 26, 2019 06:14 AM

    Just got i to work, but im not getting the logoff option in the enforcement profile, is that a 6.8 thing? im only on 6.7.9, but about to opgrade to 6.8 next month.