Configuring Third-party Devices

This section lists sample configurations for configuring third-party devices in Central NAC:

Unified RADIUS & CoA Configuration Table for Third-party Devices

The following table lists the parameters and values for all vendors:

Table 1: Generic Configuration Parameters for All Vendors

Parameter

Value

RADIUS Server IP / RADIUS Accounting Server IP

<ArubaOS Gateway IP>

Authentication Port

1812

Accounting Port

1813

Shared Secret

Radius Proxy Secret

Default CoA Port

3799

Note:

Standard configurations must be applied for Authentication, Accounting, and Change of Authorization.

Cisco Switch

! Include Framed-IP-Address in Access-Request radius-server attribute 8 include-in-access-req ! Send original Called-Station-Id (SSID + BSSID for Wi-Fi) radius-server attribute 30 original-called-number ! Set default Filter-Id direction (inbound/outbound as needed) radius-server attribute 11 default direction <in|out> ! Send detailed Calling-Station-Id (AP name, slot, VLAN, etc.) radius-server attribute 31 send nas-port-detail ! Dynamic authorization port configuration aaa server radius dynamic-author port 3799

Cisco Controller/AP

! Enable aaa override in profile configuration aaa-override ! Dynamic authorization port configuration aaa server radius dynamic-author port 3799

Note:
  • Configurations provided for the third-party devices are applicable only to specific models.

    Example: Cisco 9300 switch and Cisco AP 9130 with EWC controller

  • For different switch or controller models, check the related commands in the specific vendor document.

  • Device support is available for Juniper MIST (Wireless) and Cisco (Wired and Wireless).