Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
Configuring Authorize Only Service on HPE Aruba Networking ClearPass Policy Manager
For Smart Card authentication to be successful, you must configure an authorize-only service in HPE Aruba Networking ClearPass Policy Manager. This is required because passwordless authentication validates the details of the user in RADIUS Remote Authentication Dial-In User Service is a networking protocol that provides centralized authentication, authorization, and accounting management for users who connect and use a network service server.
For information about how to configure smart card authentication, see Smart Card Authentication.
Prerequisites
Note the following points while configuring enforcement service:
- Ensure that you have access to the ClearPass Policy Manager instance.
- Only the admin user can configure the enforcement service.
- If no role is defined in RADIUS response for the User, Central does not allow access to the user.
- If no group is defined in RADIUS response for the User, Central does not allow access to the user.
Add an Authorize-Only Service
These instructions are specific to Smart Card authentication. To configure authorize-only enforcement service for the smart card, complete the following steps:
- In ClearPass Policy Manager, navigate to > .
- Click
Add at the top right corner of the page. - In the Services tab, specify the following:
- Type—Select the Radius Authorization from the drop-down list.
- Name—Specify a unique name to indicate the service for smart card authentication.
- Description—Enter the corresponding details of the service.
- Monitor Mode—Disabled.
- More Options—Select Authorization.
- In the Roles tab, specify the following:
- Role Mapping Policy—Select the policy created for RADIUS server from the drop-down list. For more information, see Configuring RADIUS Service in HPE Aruba Networking ClearPass Policy Manager.
- In the Enforcement tab, specify the following:
- Enforcement Policy—Select the policy created for RADIUS server from the drop-down list. For more information, see Configuring RADIUS Service in HPE Aruba Networking ClearPass Policy Manager.
-
Click Save.
The service is successfully created.
For complete details about how to add a service, see Adding Services topic in ClearPass Policy Manager User guide.
Figure 1 Services Tab
Figure 2 Roles Tab
Figure 3 Enforcement Tab