Cloud Managed Networks

 View Only
  • 1.  Central NAC - problem with wired authentication

    Posted 2 days ago

    I'm having problems with setting up wired authentication from a CX 6100 to Central NAC. I have configured all the policies and profiles, but I never see authentication attempts. 

    If I go to the switch and run "show radius-server detail" I see the following output:

    Server-Name                     : euw1.cloudguest.central.arubanetworks.com
    Auth-Port                       : 2083
    Accounting-Port                 : 2083
    VRF                             : default
    TLS Enabled                     : Yes
    TLS Connection Status           : tls_connection_failed
    Initial TLS Connection Timeout  : 30 seconds 
    Timeout                         : 20 seconds 
    Auth-Type                       : pap
    Resolved-Address                : 3.126.68.5
    Server-Group:Priority           : sys_central_nac:1
    Tracking                        : disabled
    Tracking-Mode                   : any
    Tracking-Method                 : access-request
    Reachability-Status             : unknown
    Tracking-Last-Attempted         : N/A
    Next-Tracking-Request           : N/A
    Port-Access Session             : keep-alive

    So it appears that the TLS connection for the RadSec between switch and Central is failing, but how could this be if this is supposedly done automatically and with the correct certificates?



    -------------------------------------------


  • 2.  RE: Central NAC - problem with wired authentication

    Posted 2 days ago

    Is TCP port 2083 allowed on the network to the Central NAC servers?

    Can you share the output of the command show events -r and show crypto pki certificate device-identity (maybe best in a DM)



    ------------------------------
    Willem Bargeman
    Systems Engineer Aruba
    ACEX #125
    ------------------------------



  • 3.  RE: Central NAC - problem with wired authentication

    Posted yesterday

    In show events -r I'm seeing a lot of entries like this one:

    2026-05-29T10:44:53.208866+02:00 6000 port-accessd[20937]: Event|7709|LOG_WARN|UMM|-|Certificate *.cloudguest.central.arubanetworks.com rejected due to verification failure (30)

    Is there a problem there?




  • 4.  RE: Central NAC - problem with wired authentication

    Posted yesterday

    I think so. Please share the output of the command show crypto pki certificate device-identity via a DM



    ------------------------------
    Willem Bargeman
    Systems Engineer Aruba
    ACEX #125
    ------------------------------



  • 5.  RE: Central NAC - problem with wired authentication

    Posted yesterday

    I just did.

    -------------------------------------------



  • 6.  RE: Central NAC - problem with wired authentication

    Posted yesterday

    Looks all good. Please can you check if the TA profile is correctly pushed to the switch?

    Config line starts with:

    crypto pki ta-profile sys_central_nac



    ------------------------------
    Willem Bargeman
    Systems Engineer Aruba
    ACEX #125
    ------------------------------



  • 7.  RE: Central NAC - problem with wired authentication

    Posted yesterday

    No, I cannot find that line. What should I do in Central to push that?

    -------------------------------------------



  • 8.  RE: Central NAC - problem with wired authentication

    Posted 20 hours ago

    the switch command to check the TA cert is installed.

    also checking the Radsec application identity.

    I am not sure when the cert gets pushed but I think it should be when you configure central NAC server group in switch system profile or AAA Authentication profile.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------