Wireless Access

last person joined: 23 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Aruba Wireless to Cisco ACS Leap

This thread has been viewed 3 times
  • 1.  Aruba Wireless to Cisco ACS Leap

    Posted Jan 16, 2020 06:38 AM

    In a migration phase from Cisco to Aruba and also ACS to Clearpass, so i need to get 1 SSID connecting to our old Cisco Radius servers to authenicate until we can migrate to clearpass.

    Issue is when we use LEAP to authicate the users as they are set to currenty we get the below, so i have allowed the 2 Aruba controllers as a source and can authicate using MS-Chap Peap etc just not Leap so it is like Radius is not getting something from Aruba with Leap anyone seen before?

    EAP_LEAP Type not configured


  • 2.  RE: Aruba Wireless to Cisco ACS Leap

    EMPLOYEE
    Posted Jan 16, 2020 06:49 AM

    Which Opmode (Encryption type) are you using?

     

    Typically you would enable "use-session-key" in the corresponding dot1x profile when using LEAP:  https://www.arubanetworks.com/techdocs/ArubaOS_85_Web_Help/Content/arubaos-solutions/1cli-commands/aaa-auth-dot1x.htm?Highlight=use-session-key



  • 3.  RE: Aruba Wireless to Cisco ACS Leap

    Posted Jan 16, 2020 07:17 AM

    WPA2-Enterprise  Leap username and Password

     

    I have enabled that session key setting on the SSID AAA profile but it did not appear to make any difference.



  • 4.  RE: Aruba Wireless to Cisco ACS Leap

    EMPLOYEE
    Posted Jan 16, 2020 07:21 AM


  • 5.  RE: Aruba Wireless to Cisco ACS Leap

    Posted Jan 16, 2020 07:22 AM

    Yes that is already set on the ACS server and it allowed Leap from my Cisco wireless controllers fine



  • 6.  RE: Aruba Wireless to Cisco ACS Leap

    EMPLOYEE
    Posted Jan 16, 2020 07:26 AM
    The WLC is typically agnostic to the eap type. The eap type is set between the radius server and the client....


  • 7.  RE: Aruba Wireless to Cisco ACS Leap

    Posted Jan 16, 2020 07:33 AM

    Yes and that is the bit that has me confused as to what the Aubra is doing differnent as it passes them on.

     

    Options for the Radius types on the ACS are below i went with IETF but the fact other non Leap authenication is working means i dont think it is that.



  • 8.  RE: Aruba Wireless to Cisco ACS Leap

    Posted Jan 16, 2020 07:42 AM

    LEAP Allow LEAP - Use to enable LEAP authentication for users accessing the network from Cisco Aironet Access Point devices.

     

    This option is ticked



  • 9.  RE: Aruba Wireless to Cisco ACS Leap

    EMPLOYEE
    Posted Jan 16, 2020 08:02 AM
    Is it hitting that rule?


  • 10.  RE: Aruba Wireless to Cisco ACS Leap
    Best Answer

    Posted Jan 16, 2020 08:36 AM

    Logs on the old ACS are limited and that is a gobal option on the acs server so i have changed the type to Cisco Aironet instead of IETF and going to try a test.