Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

aaa authentication mgmt will not get inherited throught two levels

This thread has been viewed 4 times
  • 1.  aaa authentication mgmt will not get inherited throught two levels

    Posted Aug 11, 2020 03:42 AM

    Hi,

     

    we tried to configure our TACACS Servers as authentication servers for our MD's.

    LauDa_0-1597131343705.png

    But the server-group was not pushed from our first level (orange, first sub-folder of Managed Networks) trought two levels to the controllers.

    LauDa_1-1597131494370.png

     

     

    The TACACS server and the TACACS server group were pushed correctly.

     

    LauDa_3-1597131524340.png

    Is this an expected behaviour that the configuration will not apply throught several levels?

    Thanks.

     

    David



  • 2.  RE: aaa authentication mgmt will not get inherited throught two levels

    Posted Aug 11, 2020 06:22 AM

    Hi,

     

    Configs done at /md level should get pushed down to lower levels ( customer groups & WLC's)

     

    Please check if you still have any pending changes ( WebUI Right hand corner)

     

    Moreover the CLI outputs attached from your end shows that server-group for mgmt auth is configured at MM level rather than MD level

     

    Please log in to CLI and share the following output:

     

    Aruba[mm] #cd /md
    Aruba [md] #show configuration pending
    Aruba [md] #show configuration committed | begin "aaa authentication mgmt"

     

    Aruba[mm] #cd /md/<name of group at first level>
    Aruba [md] #show configuration pending
    Aruba [md] #show configuration committed | begin "aaa authentication mgmt"

     



  • 3.  RE: aaa authentication mgmt will not get inherited throught two levels

    Posted Aug 14, 2020 09:29 AM
    There were no pending changes.... We checked multiple times.


  • 4.  RE: aaa authentication mgmt will not get inherited throught two levels

    Posted Aug 15, 2020 07:18 AM

    I think for admin account, it is per-device settings. 

    Try make admin account on MM, it will not be replicated/pushed to MD..

     

     

    Best Regrards

    Yopianus Linga



  • 5.  RE: aaa authentication mgmt will not get inherited throught two levels

    Posted Aug 21, 2020 05:51 AM

    Hi,

     

    Please share these outputs:

     

    Please log in to CLI and share the following output:

     

    Aruba[mm] #cd /md
    Aruba [md] #show configuration pending
    Aruba [md] #show configuration committed | begin "aaa authentication mgmt"

     

    Aruba[mm] #cd /md/<name of group at first level>
    Aruba [md] #show configuration pending
    Aruba [md] #show configuration committed | begin "aaa authentication mgmt"



  • 6.  RE: aaa authentication mgmt will not get inherited throught two levels

    Posted Aug 28, 2020 08:30 AM

    We configured our TACACS Servers in the lower sub folder.

    Unfortunately it was the only way for us to get it running.



  • 7.  RE: aaa authentication mgmt will not get inherited throught two levels
    Best Answer

    EMPLOYEE
    Posted Aug 28, 2020 09:19 AM

    If you haven't, please open a technical support case in parallel so that they can replicate the issue in your environment.