Wired Intelligent Edge

 View Only
last person joined: yesterday 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

Aruba CX 6200, version 10.10, not applying LUR

This thread has been viewed 29 times
  • 1.  Aruba CX 6200, version 10.10, not applying LUR

    Posted Mar 26, 2024 05:00 AM

    Hi guys, 

    we successfully introduced 802.1x/EAP-TLS with Microsoft NPS on Aruba AOS-S 2930f switches, now we try to configure the same on Aruba CX. 

    The authentication of attached clients is fine, but we are struggeling with two things:

    1) We need to use a reduced Framed MTU Size in the NPS policies because some radius servers are only reachable via VPN. 

    Not much of a deal, but the Aruba CX switch automatically creates a RADIUS_xxxxx port-access role and maps the reduced MTU to the client ports, although aaa authentication port access radius-override is _not_ enabled. According to the AOS-CX 10.10 Security Guide only the configured Local User Role should be applied, even when the radius server has radius attirbutes configured like Framed MTU Size.

    2) None of the Local User Roles "auth-role" is applied to the client ports, although we specified them in the port configs.. This only works when we handover the name of the role by an according Radius Attribute "Aruba-User-Role" in NPS. 

    At least that works, but we would like to know why the switch seems to ignore the LUR "auth-role" by default.

    Cheers



  • 2.  RE: Aruba CX 6200, version 10.10, not applying LUR

    Posted 26 days ago

    Auth-Role will be applied when there is no radius attributes supplied by the radius sever , not necessarily user-role attribute. In your case you have provided MTU, hence auth-role was not applied. You can try mixed-role feature - radius-override to enable both the roles.



    ------------------------------
    Shobana
    Aruba
    ------------------------------