XMC 8.5.6.17 and Aruba 2920
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎02-14-2022 09:43 AM
Good Morning, is possible use XMC as NAC to control Aruba switches ?
Thanks
Giuseppe
Thanks
Giuseppe
12 REPLIES 12
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎03-31-2022 05:35 AM
----SOLVED-----
Good Morning
Finally I have found the way to use the NAC to authtenticate devices on Aruba2920 or newer
CONTROL --> ACCESSCONTROL --> ENGINE --> SWITCHES --> RADIUS ATTRIBUTES
Tunnel-Private-Group-Id=%VLAN_ID%
Tunnel-Type=13:%CUSTOM1%
Tunnel-Medium-Type=6:%CUSTOM1%
Egress-VLAN-Name=%CUSTOM1%
Egress-VLANID=%CUSTOM1%
CUSTOM1 can be 1VLANNAME for tagged port and 2vlanname for untagged port
Thanks for your support
have a nice day
Giuseppe
Good Morning
Finally I have found the way to use the NAC to authtenticate devices on Aruba2920 or newer
CONTROL --> ACCESSCONTROL --> ENGINE --> SWITCHES --> RADIUS ATTRIBUTES
Tunnel-Private-Group-Id=%VLAN_ID%
Tunnel-Type=13:%CUSTOM1%
Tunnel-Medium-Type=6:%CUSTOM1%
Egress-VLAN-Name=%CUSTOM1%
Egress-VLANID=%CUSTOM1%
CUSTOM1 can be 1VLANNAME for tagged port and 2vlanname for untagged port
Thanks for your support
have a nice day
Giuseppe
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎03-16-2022 11:36 AM
Hello,
Unfortunately I can't see the attached file you sent in. One issue I think you may be running into is that you're missing the tunnel tag for tunnel-private-group-id:
Tunnel-Private-Group-Id=%VLAN_ID%:%VLAN_TUNNEL_TAG%
Per RFC 3580:
When Tunnel attributes are sent, it is necessary to fill in the Tag field. As noted in
The Tag field is one octet in length and is intended to provide a means of grouping attributes in the same packet which refer to the same tunnel. Valid values for this field are 0x01 through 0x1F, inclusive. If the Tag field is unused, it MUST be zero (0x00)
Can you send a screenshot of the hex output for the Egress-VLAN AVP?
Thanks
-Ryan
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎02-15-2022 02:14 AM
I have configured the switch to authenticate itself on NAC, Error.docx show what I see.
Thanks
Giuseppe
Thanks
Giuseppe
