Hi,
I have 2930 switches configured to use local and downloadable user roles. one part of the configuration defines a role that will be used if the switch is unable to download roles from a clearpass appliance.
In my setting the critical role just does an "allowall" acl group on a client connected to the statically defined vlan for a specific port.
The problem is that when my switch fails to connect to clearpass theres nothing in the switch logs to indicate its using the critical-auth user-role setting.
As an example, my home net has clearpass running under VmWare Fusion .. on a mac that doesnt automatically power up after a power outage. This mess that when power is restored the switch will come back ... and all my APS but clearpas doesn't until i power it up.
While the switch logs show tht they are unable to connect to a radius server, thers nothing about the critial auth user-role being used.
If you have devcie fingerprinting enabled you can put some config in so your log file isnt swamped with messages about device fingerprinting ... is there something similar that would allow us to see when a downloadable user role is used and when a local one is used?
Rgds
Alex