- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-12-2024 08:28 AM
Hi everyone,
I am trying to get TACACS working between our PA and Aruba Clearpass authentication server. I have successfully done this for full admin as well as a custom role on the firewall. I am however running into issues with a service account logging in with read only access.
When I try to login to the local firewall with this service account I get the message "Not authorized to access" (please see screenshot PACLP1.PNG). This is further confirmed by the firewall systems logs (please see screenshot PACLP2.PNG). The role name that I specified in Clearpass is correct however, I copied and pasted the name from the local firewall account role into Clearpass so this should be fine (please see screenshot PACLP3.PNG).
This worked fine with the local firewall account but something is wrong with the authorization of this Clearpass integration. Not sure if this matters but when the service account was local on the firewall and working it was using Radius but with this Clearpass integration I'm using TACACS. I don't think this is an issue as 2 different types of login (normal firewall superuser as well as a custom role) work fine. Can anyone please advise. Thank you in advance.
08-12-2024 02:49 PM
Try using superreader as the value, that's what the firewall actually uses on the backend.
08-12-2024 08:47 AM
Update - I created a custom role on the firewall and made it as read-only as I can and that works fine. Am I not able to successfully reference the dynamic firewall Superuser (read-only) role? This works for the dynamic Superuser role so I thought it would work.
08-12-2024 02:49 PM
Try using superreader as the value, that's what the firewall actually uses on the backend.
08-15-2024 09:07 AM
Hi,
Sorry for the delay. Many thanks for that advise, I'll try that tomorrow and let you know.
08-19-2024 08:33 AM
Thank you Bpry, adding superreader instead worked 🙂
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!