Security

 View Only
  • 1.  clearpass radius accounting proxy

    Posted Apr 08, 2025 07:32 AM

    hi Airheads,

    anyone have any experience of setting up accounting proxy ?

    Customer wants Clearpass to send accounting IETF Class attributes back to Aruba Central (subject to RADIUS Accept) and

    Central to proxy accounting info to another server.

    cheers

    Pete



  • 2.  RE: clearpass radius accounting proxy

    Posted Apr 08, 2025 10:47 AM

    hi Airheads,

    just some digging around about RADIUS proxy and i think my earlier post, on this subject doesn't make sense.

    i can see that the proxy radius accounting is sent on to another RADIUS server to process.

    The customer is putting together a list of IETF Class attributes to send on to the proxy.

    The customer will provide IETF RADIUS Class attributes to be added for ACCONTING proxy.

    question how do i know what RADIUS attibutes are to be deleted (see screenshot) ?




  • 3.  RE: clearpass radius accounting proxy

    Posted Apr 08, 2025 07:53 PM

    you can send put all sort of values in Filter-Id to be sent to the accounting proxy. Normally in my deployments, I use user roles in this form.

    Here in the "role" tab, I have a role mapping policy that puts the users in their appropriate TIPS roles and that is what I am sending to the proxy with Filter-Id.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 4.  RE: clearpass radius accounting proxy

    Posted Apr 09, 2025 09:26 AM

    thank you for getting back,

    we have set up the Accounting Proxy as you have suggested and it works just fine , but at the moment only with 1 x TIPS role assignment.

    we can see the TIPS role being passed onto the Fortigate firewall, however some users (that have been assigned TIPS roles through RADIUS authentication) are

    not being proxied over.

    any ideas ?

    cheers

    Pete