HPE7-A08 · Question #91
You recently added HPE Aruba Networking ClearPass as an authentication server to a group in HPE Aruba Networking Central. RADIUS authentication with Local User Roles (LUR) works fine, but the same…
The correct answer is B. Add the correct values for "CPPM Username" and "CPPM Password" in the authentication server. Downloadable User Roles require the Aruba infrastructure to actively query ClearPass via its API to retrieve role definitions - unlike Local User Roles, which are stored on the device itself and need only a basic RADIUS exchange to work. Configuring the CPPM Username and CPPM…
Question
You recently added HPE Aruba Networking ClearPass as an authentication server to a group in HPE Aruba Networking Central. RADIUS authentication with Local User Roles (LUR) works fine, but the same access points cannot use Downloadable User Roles (DUR). What should be corrected in this configuration to fix the issue with DUR?
Options
- AAdd a new Enforcement Policy of type "WEBAUTH" on ClearPass and associate it with the
- BAdd the correct values for "CPPM Username" and "CPPM Password" in the authentication server
- CUncheck the "Dynamic Authorization" checkbox in the authentication server configuration on HPE
- DModify the shared secret on the switch to match CPPM using the "radius-server host" command
How the community answered
(22 responses)- A9% (2)
- B82% (18)
- C5% (1)
- D5% (1)
Explanation
Downloadable User Roles require the Aruba infrastructure to actively query ClearPass via its API to retrieve role definitions - unlike Local User Roles, which are stored on the device itself and need only a basic RADIUS exchange to work. Configuring the CPPM Username and CPPM Password in the authentication server settings gives Aruba Central the credentials it needs to authenticate to ClearPass and pull down those role definitions; without them, the API calls fail silently while RADIUS auth continues working fine.
Option A is wrong because a WEBAUTH enforcement policy is for captive portal flows, not role download via API. Option C is wrong because unchecking Dynamic Authorization would break features like RADIUS CoA, not fix DUR - DUR still depends on that communication channel. Option D is wrong because the shared secret governs RADIUS packet authentication, which is already working (LUR proves this), so the secret is not the problem.
Memory tip: Think of CPPM Username/Password as the "API key" - LUR only needs the RADIUS handshake (already working), but DUR needs ClearPass to open its door and hand over role data, which requires valid credentials to get in.
Topics
Community Discussion
No community discussion yet for this question.