Higher Education

 View Only
last person joined: 21 days ago 

Got questions on how to enable mobility in education? Submit them here!
Expand all | Collapse all

Aruba 8320 does not support login from switch to Clearpass for RADIUS authorization?

This thread has been viewed 6 times
  • 1.  Aruba 8320 does not support login from switch to Clearpass for RADIUS authorization?

    Posted Mar 12, 2024 02:27 PM

    Hello,

    I am attempting to harden our 8320s used as core switches to require domain login instead of local switch admin login. I have a fleet of 6200F used as edge switches and this works flawlessly using:

    switch(config)# radius-server host clearpass.*.* key plaintext secretkey clearpass-username user clearpass-password plaintext password

    When I attempt the same on the 8320 switch I get:

    Invalid input: clearpass-username

    Does the 8320 not support this feature although the 6200F does?

    Thank you for taking the time to read. If anyone has any ideas that would be great.



  • 2.  RE: Aruba 8320 does not support login from switch to Clearpass for RADIUS authorization?
    Best Answer

    Posted Mar 12, 2024 03:01 PM

    If you are just using RADIUS for system login, you do not need the "clearpass-username" and "clearpass-password" attributes. Those are for the downloadable user roles function. 



    ------------------------------
    If my post was useful, please Accept Solution and Give Kudos.
    ------------------------------
    Zak Chalupka
    Principal Engineer - HPE Aruba
    ACDX | ACMP | ACSP | ACCP
    wifizak@hpe.com
    ------------------------------
    Ideas expressed here are solely my own and not necessarily that of HPE Aruba.
    ------------------------------



  • 3.  RE: Aruba 8320 does not support login from switch to Clearpass for RADIUS authorization?

    Posted Mar 13, 2024 04:21 PM

    That is exactly what I needed to know. Knowing I was barking up the wrong tree looking at the switch config, I switched over to clearpass and located my problem. Embarassibngly the device I added had to clearpass the wrong IP address assigned to it. Once I fixed that it worked. Thanks 802.zak! 

    TS