Airheads Community
Skip to content
  • Discuss
    • All Discussions
    • Technology Discussions
    • Community
    • Industry
    • Global Forums
  • Knowledge Bases
    • Knowledge Bases
    • Support Knowledge Base
    • Airheads Knowledge Base
  • Technical Product Details
    • Networking Products
    • Security Products
    • Location Services Products
  • Learning
    •     
    • Intro To Aruba
    • Airwave Network Management
    • Analytics
    • Instant
    • Central Network Management
    • Wired Switching
    • Activate
    • AAA & ClearPass NAC
    • Wi-Fi Design
    • Controllers & APs
    • Meridian Mobile Engagement
    • Product Updates
  • News & Events
    •     
    • Community News
    • Community Events
    • AMFX Hall of Fame
  • Menu
  • Member Login
  • Register
  • Global Forums

Global Forums

  • English
  • Norsk
  • 中文讨论区
  • Polska

Welcome Back!

Select your Aruba account from the following:

  • Aruba Central

    Login to your cloud management instance

  • Partner Ready for Networking

    Login to access partner sales tools and resources

  • Airheads Community

    Login to connect, learn, and engage with other peers and experts

  • Tech Field Day
    hosted at Aruba.

    Join us live!

  • The Era of the Modern Network is Here

    Switch Forward

  • Gartner gives HPE (Aruba) the
    highest score in 5 of 6 use
    cases

    Read the blog

  • Live at the Edge with
    Aruba Unplugged

    Listen now

  • Posts
  • Users

Search the Community

Showing results for 
Search instead for 
Did you mean: 
Search Options
  • Subscribe to RSS Feed for this Search
Advanced Hide Advanced
Advanced Search Options
Search Modifiers:
You can apply modifiers to the terms you enter in the search field.
Use quotes to search for an "exact phrase".
Use the plus sign to search for +one +or +more +words.
Use the minus sign to -exclude -certain -words from your search.
Limits search results to topics that have no replies.
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
  • in Discuss
30,000 results
Sorted by:
Best Match
  • Date
  • Views
  • Kudos
  • Replies
  • Best Match

Downloadable Users Roles - Profile for Access Points

by REgan in Security
‎08-16-2019 06:03 PM
‎08-16-2019 06:03 PM
Hello,   I'm having an issue whereby I'm sending downloadable user roles from ClearPass to an Aruba Switch (2930F - v16.09.003). Specifically, I've created a profile for an access point to b...
Labels:
  • CPPM
Show results in replies (1)
  • ...learPass in the standard downloadable user role configuration since 6.8. It is explained in the Access S...

Downloadable User Roles CPPM and Aruba 2930F

by alexsuoy MVP Expert in Security
‎03-06-2018 01:47 AM
‎03-06-2018 01:47 AM
...hromecast device against clearpas tries to use a downloadable role but fails and uses the local mydelault-role instead.   With debugging turned on we see   0006:18:31:41.03 CRYP m...
Labels:
  • CPPM
Show results in replies (3)
  • ...he switch, it helps if you don;t use the intermediate CA from the RADIUS service but the one from the H...
  • Yes, I have this implemented with ClearPass 6.7.1 and WC.16.05.0004 on the switch. &n...
  • ..._7Z4q to macAuth client B827EB63DF46 on port 2/11: user role is invalid. 0001:20:52:12.56 MAC m...

Clearpass CoA with ArubaOS switch

by mPeter in Security
‎06-18-2019 09:51 AM
‎06-18-2019 09:51 AM
I want to change user role of a ArubaOS-Switch client with Clearpass CoA, however I can't get it work.   using CP RADIUS Dyn Authorization Template: ArubaOs Switching-Change User Role, but m...
Labels:
  • CPPM
Show results in replies (1)
  • ...etworking/docs/switches/WB/15-18/5998-8152_wb_2920_asg/content/ch06s04.html#s...

Downloadable roles on CPPM

by zaffiro in Security
‎11-09-2017 03:23 AM
‎11-09-2017 03:23 AM
Hi community,   I'm testing downloadable roles feature on CPPM. I have defined a very simple rule to just assign vlan for users when they successfully authenticate. Below is my enforcement p...
Labels:
  • CPPM
Show results in replies (9)
  • ...ttribute, and only use downloadable roles to assign ACL to users. It works fine now.   Thank you all,
  • ...version 8.2.0.1. Can downloadable roles work with this deployment? Or does it only work with s...
  • ...eauthenticating client 94F1288B1234 on port 1/23, downloaded user role DUR_TEST is not v...
  • Did you enabled the downloadable functionality under the aaa profile ? Get Outlook for iOS
  • ...e tagged VLAN in User-Roles ;)
  • ...hen using DUR.   We're currently using vlan-id xxxx in the HPE-CPPM-Role but the VLANs keep c...
  • The limit isn't in DUR - it's in the User-Role. Found that out when I tried working around the p...
  • Did you try this with more than one tagged VLAN? On the switch (show vlan interface 1) I'm not s...
  • How would one pass tagged VLANs using DURs?   'vlan-id' or 'vlan-name' seem only to be f...

CPPM Downloadable Roles with Application Authentication

by zemerick1 in Security
‎11-05-2019 12:54 PM
‎11-05-2019 12:54 PM
CPPM 6.7.12 I'm setting up switch DUR for a wired guest authentication scenario.   1. User is initially redirected to Web Login (App Auth service) 2. User logs in and receives DUR. (Issue h...
Labels:
  • CPPM
Show results in replies (3)
  • ...For your second question: What you could do, is once the user completes the captive portal, t...
  • ...ays to create an Application Service to handle the captive portal logins in conjuction with DURs.&n...
  • It seems the best way is to use the Wired guide that @Tim keeps up to date.  1. Create W...

CPPM + 2930F - Downloadable User Roles Failing

by REgan in Security
‎08-03-2019 05:48 PM
‎08-03-2019 05:48 PM
...RadiusR:Received cppm downloadable user role vsa for client with request-id 28 and assigned user role is : Aruba_DUR_Data_Allow_All-3016-5 0002:05:39:33.75 UMIB mdcaCtrl:New node is created for t...
Labels:
  • CPPM
Show results in replies (2)
  • I found some errors in the above policies but I did get the revised roles to be accepted in the switch...
  • Fixed it!   Switch clock was wrong. Reset it w/ NTP and the DURs started working!

Downloadable User Role is invalid message

by alexsuoy MVP Expert in Wired Intelligent Edge (Campus Switching and Routing)
‎06-06-2019 07:25 AM
‎06-06-2019 07:25 AM
...et up Per User Tunnelling Node link for a Chromecast deice tha tunneled data up to our ArubaOS 8 mobility controller.   I then went back to one supposedly for a dhcp fingerprinted AP to drop it i...
  • Tags:
  • dur
Show results in replies (2)
  • ...ried running "debug security"?  That should give you the exact line the user role is failing on.
  • ...04C033A6089 on port 2/13: user role is invalid.   However, The user role I'm passing back ( based u...

difference between downloadable acl and downloadbale User Roles

by niklaskarg in Security
‎09-19-2019 11:43 AM
‎09-19-2019 11:43 AM
Hello im searching for a information source about the main differences between downloadable User Roles and dacl. We have a mixed environment with 2530 and 2540 switches. The documantation for c...
Labels:
  • CPPM
Show results in replies (2)
  • Downloadable user roles should always be preferred.   It gives you more flexibility. A use...
  • ...xplanation on the concepts in the first episodes.   Also note that you can have local user roles on t...

Captive Portal - Role / VLAN Assignment

by airhead1234 in Wireless Access
‎12-21-2016 07:05 PM
‎12-21-2016 07:05 PM
AAA with inital Role for Captive Portal Redirect - Works fine   CPPM passes back a Guest role after proper authentication - Seems OK too   The Guest Role as defined on the controller h...
  • Tags:
  • CPPM
  • guest
Labels:
  • Controllers
Show results in replies (5)
  • ...LAN with your RADIUS authentication. 2) For the captive portal (extension of what Tim answered), t...
  • You can not reliably flip a VLAN on a captive portal user because they already have an IP address.
  • For others reading this.. I sent Aruba Terminate enforcement after Captive Portal auth. The user c...
  • ...uest.. such as a Contractor on the appropriate VLAN.    Maybe I CoA the user after i...
  • You may want to consider using server-initiated login then instead of controller login so you can e...

ClearPass assigned Voice VLAN on ArubaOS switches with LLDP-MED

by Chris.Denham in Wired Intelligent Edge (Campus Switching and Routing)
‎11-14-2018 02:21 PM
‎11-14-2018 02:21 PM
...his a supported configuration? Is there a way to achieve this using user roles on the switch?
Labels:
  • ClearPass
Show results in replies (7)
  • ...VOICE' results in the VLAN with the name 'VOICE' being tagged on the switch port and is also helpful if y...
  • ...bsp; I seem to recall that the port has to be tagged with the VLAN before LLDP MED can be a...
  • Any info on what the changes will be? :)
  •   @Chris.Denham wrote: Any info on what the changes will be? :) Look r...
  • @rwilsonblue wrote: Thanks for the info. One would think there would be a best practice f...
  • From the release notes, for posterity:   Bypassing Authentication for VoIP phones With 16.08...
  • Bypassing authentication for phones is NOT recommended. You should assign a voice role.
  • « Previous
    • 1
    • 2
  • Next »
  • COMPANY
    • About Us
    • Careers
    • Contact Us
    • Leadership Team
    • Environmental Citizenship
    • HPE.com
  • NEWS & EVENTS
    • News Releases
    • Atmosphere
    • Events
    • Webinars
    • News Coverage
  • SUPPORT
    • Support Services
    • Contact Support
    • Aruba Education Services
    • Professional Services
    • Software Downloads
    • Licensing Login
  • PARTNERS
    • Find a Partner
    • Become a Partner
    • Partner Ready for Networking
    • Technology Partner Programs
  • RESOURCES
    • Case Studies
    • Product Documentation
    • Multimedia
    • Resource Library
    • Blogs

Follow Us

Airheads Twitter Linkedin Facebook Youtube
  • Privacy policy
  • Terms of service
  • Site Map
  • Legal
 Aruba Networks

© Copyright 2019 Hewlett Packard Enterprise Development LP
All Rights Reserved.
Powered by Lithium

Please share website feedback