Wired Intelligent Edge

 View Only
last person joined: yesterday 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

CX Switch Downloadable Roles Error message

This thread has been viewed 10 times
  • 1.  CX Switch Downloadable Roles Error message

    Posted Mar 05, 2024 12:10 PM

    Hello forum,

    I have a lab where I am connecting an Aruba Central managed CX switch via a firewall to Clearpass as radius server. The client works with MAC-based authentication via Clearpass. This works well until the switch tries to download the role from Clearpass. The command "show port-access clients detail" shows that the client is authenticated but role download fails:

    **************

    Authorization Details

      ----------------------

        Role   : OT_Lab2-3066-2

        Status : Download Failed

    Role Information:

    Name  : OT_Lab2-3066-2

    Type  : clearpass

    Status: Failed, Server Credentials Not Found

    *********************************************

    The switch does not even try to connect to Clearpass via https (firewall logs show that). So it seems to be a config issue on the switch. The config had to be changed via CLI and "aruba-central support-mode because in Central, I cannot add the required commands for DUR:

    radius-server host xyz.de key ciphertext KEY clearpass-username ot-lab clearpass-password ciphertext CYPHER

    I'm sure I made a mistake during config. But where to look?



  • 2.  RE: CX Switch Downloadable Roles Error message
    Best Answer

    Posted Mar 05, 2024 12:15 PM

    Do you have the ClearPass server's HTTPS certificate loaded onto the switch?

    See this post about loading the certificate. You will have to do this in the CLI with Aruba Central Support mode enabled.

    AOS-CX Downloadable User Role (DUR) simple steps to Configure! | Wired Intelligent Edge (arubanetworks.com)




  • 3.  RE: CX Switch Downloadable Roles Error message

    EMPLOYEE
    Posted Mar 05, 2024 04:22 PM

    that specific error could also point to the fact that you many not have created a user credentials that the CX switch will use to download the user role from ClearPass.

    Here is the corresponding switch command

    radius-server host victory2.arubatechs.com key plaintext sdsda clearpass-username cx-dur clearpass-password ciphertext sdsds vrf mgmt.

    you can refer to this technote Aruba ClearPass Wired Enforcement for CX switches – Part5



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 4.  RE: CX Switch Downloadable Roles Error message

    Posted Mar 06, 2024 01:35 AM

    Thank you for your replies. In the meantime, I sorted this out. The error was myself using not the correct FQDN for Clearpass. This did not fit to the certificate which I indeed had to paste via CLI.

    A big help was the Airheads video series for Dynamic Segmentation on Youtube. Thank you for that!