Security

 View Only
last person joined: 23 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM Accounting for VIA (Central)

This thread has been viewed 8 times
  • 1.  CPPM Accounting for VIA (Central)

    Posted Nov 28, 2022 06:23 AM
    Hi all,

    we want to implement accounting with VIA VPN using AOS8 VPNCs in Central.

    We have configured ClearPass as authentication server for EAP-TLS and it all works. But we also want to send accounting data to CPPM, so we also configured CPPM as accounting servers. But in ClearPass we can not see any accounting session for the users, only the authentication in the Access Tracker.

    Do I have to enable more than this:
    I can't find any more settings for accounting with VIA.

    I only found this old community post, but it looks like it only refers to the shown setting:
    https://community.arubanetworks.com/browse/articles/blogviewer?blogkey=fa105723-0df2-4f4a-b3fe-861aa70513d9 

    I have confirmed that this settings are applied on the gateway:
    VIA Authentication Profile "default"
    ------------------------------------
    Parameter                                                         Value
    ---------                                                         -----
    Default Role                                                      deny-all
    Server Group                                                      cppm
    RADIUS Accounting Server Group                                    cppm
    Max Authentication failures                                       0
    Description                                                       N/A
    Check certificate common name against AAA server                  Disabled
    Client-certificate based authentication for VIA Profile download  Disabled
    Authentication protocol                                           pap
    RFC 3576 server                                                   X.X.X.216
    RFC 3576 server                                                   X.X.X.217
    PAN Firewall Integration                                          Disabled
    Download Role from CPPM                                           Disabled
    Encoding format for the user credentials                          utf-8
    ​

    Has someone done this with or without Central and can give some hints on what I should look for?

    ------------------------------
    Thanks,
    Bjarne
    ------------------------------


  • 2.  RE: CPPM Accounting for VIA (Central)

    Posted Nov 29, 2022 11:30 AM
    Hi, have you tried to uncheck the Laod Balance option and see if it works?