Configuring RADIUS Service in HPE Aruba Networking ClearPass Policy Manager

For RADIUS Remote Authentication Dial-In User Service is a networking protocol that provides centralized authentication, authorization, and accounting management for users who connect and use a network service Authentication, you must configure the RADIUS Enforcement service in HPE Aruba Networking ClearPass Policy Manager.

Prerequisites

Note the following points while configuring enforcement service in ClearPass Manager:

  • Ensure that you have access to the ClearPass Policy Manager instance.
  • Only the admin user can configure the enforcement service.
  • If no role is defined in RADIUS response for the User, Central does not allow access to the user.
  • If no group is defined in RADIUS response for the User, Central does not allow access to the user.

To configure the RADIUS enforcement service in ClearPass Policy Manager, follow the steps mentioned in ClearPass Policy Manager User guide available at HPE Networking Support Portal.

Configuration Steps

To configure RADIUS enforcement service, complete the following steps:

  1. In ClearPass Policy Manager, navigate to Configuration > Services.
  2. Click Add at the top right corner of the page.
  3. In the Services window, click the Authentication tab.
  4. Select the Strip Username Rules check box to pre-process the username (to remove domain suffix) before authenticating and authorizing against the authentication source.

    For more information, see step Figure 1.

  5. Under Configuration > Enforcement > Profiles, click Add at the top right corner of the page.
  6. In the Enforcement Profiles window, click the Attributes tab.
  7. Configure the attributes described in step Table 1.

  8. For more information, see Adding Services topic in ClearPass Policy Manager User guide.

The following table describes the attributes for RADIUS enforcement profile.

Table 1: Attributes table

Type

Name

Value

Radius:Aruba

Aruba-Admin-Role

Select the role assigned to the user

Radius:Aruba

Aruba-Admin-Device-Group

Select the group assigned to the user.

Comma-seperated option can be used when multiple groups are assigned.

If the user has access to all groups, then the allgroups value can be provided.

The following figure displays the authentication configuration page for RADIUS enforcement service.

Figure 1  Sample Figure for Services

The following figure displays the user attributes configuration page for RADIUS enforcement profile.

Figure 2  Sample Figure for role and groups assignment