Wired Intelligent Edge

 View Only
last person joined: 8 hours ago 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

Detecting fingerprint data in CX usin g RADIUS Accounting

This thread has been viewed 11 times
  • 1.  Detecting fingerprint data in CX usin g RADIUS Accounting

    MVP EXPERT
    Posted 11 days ago

    Hi,

    Most of my auth / DUR stuff has been on. ArubaOS-S/ Mobiltiy Controllers ... now dipping toe in for CX, so ... running. 10.13.x code ( whatever the latest is) ,have configured  DUR usage and.  am using RADIUS accounting to upload fingerprint data to cppm ...so got a few questions

    1). sh port-access shows that i have an authentication. with a DUR applied

    2). cppm shows both. dot1x and mac auth ( yes the switch is configured to do both to speed things up)

    The DUR says 

    • Apply an allow all ACL
    • Reauthenticate every hour
    • switch port into client-mode
    • Do not define any tagged/iuntagged vlans use the statically assigned one

    For the client

    The reauth isnt 1 hour but a few mins

    The client isnt  obtaining an IP address from the dhcp server even though its on the correct vlan

    Whats the CX equivalent. of sh user-role download detail ?

    How can i tell that the client fingerprint data has been uploaded via RADIJUS accounting?

    Rgds

    Alex



  • 2.  RE: Detecting fingerprint data in CX usin g RADIUS Accounting

    MVP EXPERT
    Posted 11 days ago

    ok so  sh port-access client detail

    Tells me that its failed to download the  DUR with an error of server certificate invalid

    but if i do a sh crypto pki ta-profile clearpass I get the  enterprise local  root CA cert.

    Should I also include the intermediate CA ?

    A




  • 3.  RE: Detecting fingerprint data in CX usin g RADIUS Accounting

    MVP EXPERT
    Posted 11 days ago

    nope guess not,  the root CA is the same one I install on ArubaOS-S switches and thats the only one there ... and both arubaos-s and arubaos-cx are both talking to the same cppm server

    switch time is correct as well

    A




  • 4.  RE: Detecting fingerprint data in CX usin g RADIUS Accounting

    MVP EXPERT
    Posted 11 days ago

    firmewware is 10.13.1010




  • 5.  RE: Detecting fingerprint data in CX usin g RADIUS Accounting

    EMPLOYEE
    Posted 11 days ago

    you can refer to this 6x parts series on Aruba ClearPass Wired Enforcement for CX switches Part1 which covers LUR, DUR and more.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 6.  RE: Detecting fingerprint data in CX usin g RADIUS Accounting

    MVP EXPERT
    Posted 11 days ago

    Many thanks for that, most informative. I notice you use an FQDN when specifying a radius server . On our 2930 estate we dont and just point  the switch at.  the cppm VIPs  The cppm certs dont have an  IP: SaN nor an FQDN associated with the cppm VIPS. Can tweak the config to test things out to see if its that I guess

    A




  • 7.  RE: Detecting fingerprint data in CX usin g RADIUS Accounting

    MVP EXPERT
    Posted 11 days ago

    And that works. If I use an FQDN when defining a radius service, the cert gets validated and things work. Can now see the DUR on the switch, the device gets an iop address and i can see RADIUS accounting packets .

    This gets me back to the original question. I've configured the switch to forward device fingerprints to cpppm via radius accounting ... and. its not working. cppm thinks the device is a ageneric HP laptop  instead of a windows device. Cant see anything on cppm radius accounting hinting tht its received the info

    So on the switch i have 

    vsa vendor aruba type avpair group dfp-client-info 

    switch is defined as being an aruba  device on cppm