Aruba CX OS-Switch Wired Layer 2 Integration

Note – In this example, an HP Aruba CX 6300M configuration is provided as tested on 10.09.1000 firmware, however any Aruba CX OS-Switch supporting the following features are eligible for integration. This integration is not intended for HPE switches running non-ArubaOS-Switch or ArubaOS software (K or Y software versions).

SafeConnect VM is <NAC-IP>

configure
!
aaa authentication port-access dot1x authenticator radius server-group SafeConnect
aaa authentication port-access mac-auth radius server-group SafeConnect
aaa authentication port-access dot1x authenticator enable
aaa authentication port-access mac-auth enable
aaa authentication port-access captive-portal-profile captive-portal
url https://portal.myweblogon.com
exit
!

radius-server host <NAC-IP> key plaintext "your-secret-here"

aaa group server radius SafeConnect
server <NAC-IP>
exit
!
aaa accouting port-access start-stop interim

radius dyn-authorization enable
radius dyn-authorization client <NAC-IP> secret-key plaintext "HelloEnforcer"

Troubleshooting command

show port-access client interface 1/1/2 detail
(Show detail overview of role port assignment)


show aaa authentication port-access interface 1/1/2 client-status
(Command on the switch will display the details of a session.)

show port-access role radius
(to see what VLAN is applied to what profile)

show radius dyn-authorization
(Command can be used to see if the COA was being acknowledge by the switch.)