Wireless Access

last person joined: 20 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Wireless authentication group membership - Cisco ACS

This thread has been viewed 0 times
  • 1.  Wireless authentication group membership - Cisco ACS

    Posted Nov 11, 2012 12:15 AM
      |   view attached

    I am trying to configure our wireless access to require a user be a member of an AD group. I'm using Cisco ACS 4.2 and have followed this KB - http://support.arubanetworks.com/ArubaOSKB/tabid/111/Default.aspx. My issue is it's still allowing everyone to authenticate successfully even though they are not a member of the group. 

     

    I can't see anywhere in the logs why it would be successful when the user isn't in the group. My test user "jmkrueger" is not a member of the required group but still gets the authenticated user role.

     

    Anyone help point out what I'm missing?

     

    Thanks,

    Justin

     

    Attachment(s)

    txt
    sh log inc authmgr.txt   37 KB 1 version


  • 2.  RE: Wireless authentication group membership - Cisco ACS

    Posted Nov 11, 2012 01:17 AM

    I've somewhat figured out my problem but it doesn't necessarily make sense to me how the controller is handling this.

     

    The default group (in ACS) that my test user was in was not setup to return any value for "Filter-ID" which to me means the authentication would fail since I thought it would be looking for the "allowaccess" attribute. It seems that if there is not a attribute returned the user is allowed access instead of denied. 

     

    To fix it I set it up to the default group to return a "denyaccess" for Filter-ID and then added a second server rule looking for that and assigning the denyall role. 



  • 3.  RE: Wireless authentication group membership - Cisco ACS

    EMPLOYEE
    Posted Nov 11, 2012 06:56 AM

    You are doing it correctly.  The only other way is if the ACS server finds that a user is NOT in an AD group, it would not return a positive result and signal to the controller access-reject.