Security

 View Only
  • 1.  ClearPass Wired Enforcement profile for Cisco switch trunk port

    Posted Aug 02, 2023 07:47 PM

    Hello,  I am setting up ClearPass wired enforcement policy with Cisco switches.  Our standard VLAN enforcement profiles work but I need to create an enforcement profile for a port connecting a Meraki AP.  The enforcement profile needs to set the port as a trunk port with multiple tagged VLANs and a native VLAN.  

    Does anyone have a template for this enforcement profile?  I have looked through the Aruba wired enforcement policy guide and searched for Cisco tagged or trunk port enforcement and have not been able to locate this one.

    Much appreciated.



  • 2.  RE: ClearPass Wired Enforcement profile for Cisco switch trunk port

    Posted Aug 03, 2023 02:58 AM

    I'm not a Cisco expert, but in the past I have seen the NEAT feature covers this scenario. The link I had to the forum has been archived, but by searching for NEAT you may be successful.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: ClearPass Wired Enforcement profile for Cisco switch trunk port

    Posted Aug 03, 2023 12:17 PM

    Thanks Herman 

    Is there not a RADIUS attribute I can send from ClearPass as an enforcement profile to set the port as tagged VLAN with a native VLAN instead of single Access 'untagged' VLAN to a Cisco switch?

    Thanks




  • 4.  RE: ClearPass Wired Enforcement profile for Cisco switch trunk port

    Posted Aug 04, 2023 02:18 AM

    Again, I'm not an expert on this, but if there were RADIUS attributes to push VLANs, it would be well-known. I now found a piece of documentation on NEAT, which mentions 'The cisco-av-pairs must be configured as device-traffic-class=switch on the ISE, which sets the interface as a trunk after the supplicant is successfully authenticated.'. You can do just the same from ClearPass.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------