Users Guide

Table Of Contents
Dell Networking W-Series ArubaOS 6.4.x| User Guide ClearPass Policy Manager Integration | 463
Chapter 18
ClearPass Policy Manager Integration
ArubaOS and ClearPass Policy Manager (CPPM) include support for centralized policy definition and
distribution. ArubaOS now supports downloadable roles. By using this feature, when CPPM successfully
authenticates a user, the user is assigned a role by CPPM and if the role is not defined on the controller, the role
attributes can also be automatically downloaded.
This chapter contains the following sections:
n Introduction on page 463
n Important Points to Remember on page 463
n Enabling Downloadable Role on a Controller on page 464
n Sample Configuration on page 464
Introduction
In order to provide highly granular per-user level access, user roles can be created when a user has been
successfully authenticated. During the configuration of a policy enforcement profile at CPPM, the
administrator can define a role that should be assigned to the user after successful authentication. In RADIUS
authentication, when CPPM successfully authenticates a user, the user is assigned a role by CPPM and if the
role is not defined on the controller, the role attributes can also be automatically downloaded. This feature
supports roles obtained by the following authentication methods:
l 802.1x (wireless and wired users)
l MAC authentication
l Captive Portal
Important Points to Remember
l Under Advanced mode, CPPM does not perform any error checking to confirm accuracy of the role
definition. Therefore, it is recommended that you review the role defined in CPPM prior to enabling this
feature.
l Attributes that are listed below, herein referred to as whitelist role attributes, can be defined in CPPM.
n netdestination
n netservice
n ip access-list eth
n ip access-list mac
n ip access-list session
n user-role
l The above attributes that are referred to by a role definition must either be defined within the role
definition itself or configured on the controller before the policy is downloaded.
l In CPPM, two or more attributes (as listed above) should not have the same name. The example below is
considered invalid, as both the attributes have test as the profile/net destination name.
qos-profile test
netdestination test