Configuring Third-party Devices
This section lists sample configurations for configuring third-party devices in Central NAC:
Unified RADIUS & CoA Configuration Table for Third-party Devices
The following table lists the parameters and values for all vendors:
Table 1: Generic Configuration Parameters for All Vendors
|
Parameter |
Value |
|---|---|
|
RADIUS Server IP / RADIUS Accounting Server IP |
<ArubaOS Gateway IP> |
|
Authentication Port |
1812 |
|
Accounting Port |
1813 |
|
Shared Secret |
Radius Proxy Secret |
| Default CoA Port |
3799 |
Standard configurations must be applied for Authentication, Accounting, and Change of Authorization.
Cisco Switch
! Include Framed-IP-Address in Access-Request radius-server attribute 8 include-in-access-req ! Send original Called-Station-Id (SSID + BSSID for Wi-Fi) radius-server attribute 30 original-called-number ! Set default Filter-Id direction (inbound/outbound as needed) radius-server attribute 11 default direction <in|out> ! Send detailed Calling-Station-Id (AP name, slot, VLAN, etc.) radius-server attribute 31 send nas-port-detail ! Dynamic authorization port configuration aaa server radius dynamic-author port 3799
Cisco Controller/AP
! Enable aaa override in profile configuration aaa-override ! Dynamic authorization port configuration aaa server radius dynamic-author port 3799
-
Configurations provided for the third-party devices are applicable only to specific models.
Example: Cisco 9300 switch and Cisco AP 9130 with EWC controller
-
For different switch or controller models, check the related commands in the specific vendor document.
-
Device support is available for Juniper MIST (Wireless) and Cisco (Wired and Wireless).