Security

 View Only
  • 1.  Aruba ClearPass and AMD Pensando PSM RADIUS Authentication

    Posted Dec 08, 2022 07:58 AM
      |   view attached

    Hi Airheads.

    Aruba CX 10000 switch is great product in it' own right. It opens new horizonts and force us to look at the bigger picture. There was a lot of talks around it from it's introduction last year.


    One component we didn't really have too much talk is Pensando Policy and Services Manager. PSM in short. Usually we talk about Fabric Composer and technicalities. 

    When I was testing PSM, it was my natural instinct to try to authorize users via ClearPass. Searching Airheads, Arubapedia, Google, AMD, Pensando... didn't return any usefull clues how to do it. Having no other option, I reach out to AMD Pensando team in Europe and thank's to them receive required information. It wasn't take much effort to configure ClearPass and PSM to successfully use RADIUS authentication.

    Attached is first version of the instructions how to do it.

    Many thanks to AMD Pensando guys in Europe. You are really great. 

    Best, Gorazd





    ------------------------------
    Gorazd Kikelj
    ------------------------------

    Attachment(s)



  • 2.  RE: Aruba ClearPass and AMD Pensando PSM RADIUS Authentication

    Posted Jul 29, 2025 10:16 AM
    Edited by mom Jul 29, 2025 10:47 AM

    Hey,

    thank you for sharing this Technical Note.
    Very useful and an important addition to the userguide.


    ------------------------------
    Best regards, mom
    ------------------------------



  • 3.  RE: Aruba ClearPass and AMD Pensando PSM RADIUS Authentication

    Posted Jul 29, 2025 11:51 AM

    Hi Mom.


    Did you find out, what went wrong?

    I usually forget to assign a user group to role bonding and then I get no access. Quite embarrassing :-) . I didn't spot this error and for workaround I add role binding of remote user manually. Now I look into my Tech Note and see my error and everything is working fine.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 4.  RE: Aruba ClearPass and AMD Pensando PSM RADIUS Authentication

    Posted Jul 29, 2025 01:21 PM

    Hello,

    I didn't expect you to notice the post so quickly.
    Thats why I was editing my original message ... if there was an delete button, I would have deleted the message, to bother no one with this ;)

    There was no missconfiguration on any side, neither at ClearPass side nor on PSM side.
    However, in between the two, there sits a legacy core router with ACLs on it.
    And the return path from ClearPass to PSM was not permitted.

    This was not expected and so, I was wondering if I missed somthing on the new systems.

    So, the guide is good and nothing is missing.

    Thank you for your answer!



    ------------------------------
    Best regards, mom
    ------------------------------



  • 5.  RE: Aruba ClearPass and AMD Pensando PSM RADIUS Authentication

    Posted Jul 29, 2025 12:01 PM
      |   view attached

    I added a new chapter on using Clearpass with PSM cluster by utilizing NAS-ID field for RADIUS device.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------

    Attachment(s)



  • 6.  RE: Aruba ClearPass and AMD Pensando PSM RADIUS Authentication

    Posted Jul 29, 2025 01:25 PM
    Edited by mom Jul 29, 2025 01:25 PM

    Hi,

    cool!
    Isn't it worth uploading this Tech Note to the NSP portal?

    Thank you!



    ------------------------------
    Best regards, mom
    ------------------------------