Wired Intelligent Edge

 View Only
last person joined: 13 hours ago 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution

Issue with Radius (Windows NPS) and Aruba 6000 Series Switches

This thread has been viewed 3 times
  • 1.  Issue with Radius (Windows NPS) and Aruba 6000 Series Switches

    Posted May 17, 2022 12:58 PM

    Hello,

     

    I'm having an issue with Windows NPS. And getting the below output in event log when attempting to radius into an Aruba 6000 series switch. I believe I need to configure a vendor specific attribute but couldn't find any clear documentation. I've seen some videos where the VSA is applied to the Network Policy but based on the reason code and the particular conditions I have leads me to believe I need to configure a VSA on the Connection Request Policy. Although I'm just not sure at this point.

    I have some HPE ProCurve's that are using the configured CRP and Network Policy and are having no issues in allowing me to connect to them over radius. Seems to only be the Aruba 6000 series. 

     

    User:

                  Security ID:                                     NULL SID

                  Account Name:                              User1

                  Account Domain:                                         -

                  Fully Qualified Account Name:   -

    Client Machine:

                  Security ID:                                     NULL SID

                  Account Name:                              -

                  Fully Qualified Account Name:   -

                  Called Station Identifier:                            -

                  Calling Station Identifier:                           192.168.X.X

    NAS:

    NAS IPv4 Address:                         -

                  NAS IPv6 Address:                         -

                  NAS Identifier:                               sshd

    NAS Port-Type:                              Virtual

                  NAS Port:                                        15263

    RADIUS Client:

                  Client Friendly Name:                   "Friendly Name"

                  Client IP Address:                                        192.168.X.X

    Authentication Details:

                  Connection Request Policy Name:           -

                  Network Policy Name:                  -

                  Authentication Provider:                            -

                  Authentication Server:                 "Authentication Server"

                  Authentication Type:                    -

                  EAP Type:                                        -

                  Account Session Identifier:                        -

                  Logging Results:                             Accounting information was written to the local log file.

                  Reason Code:                                 49

                  Reason:                                                         The RADIUS request did not match any configured connection request policy (CRP).

     

    Thank you in advance if anyone has any information regarding my issue.



    ------------------------------
    Austin
    ------------------------------