[tac_plus] Aruba tacacas ...PAP issue
Mraz, Peter
pmraz at emea.att.com
Thu Jul 4 12:59:33 UTC 2013
Hello
I'm using your script for cisco routers,switches, juniper routers/switches, cisco WLC.
Last couple of days I'm trying to do the same for Aruba WLC.
I'm in trouble with something, what I dont know fix.
This works to me for Aruba
user = pm7625 {
login = file /etc/passwd
member = admins
pap = cleartext "aruba"
}
But I need something what I have for other devices :
user = pm7625 {
login = file /etc/passwd
member = admins
}
so take password from file /etc/passwd ....but I tried all what I found and this is not working.
this is specification of admins ....
group = admins
{
default service = permit
service = AMP
{
role = "AMP Administrator"
}
}
aruba config :
aaa authentication-server tacacs "135.76.4.10"
host 135.76.4.10
key 037e87c987c2d34e6dedb5b58c544b7c9a01d699a0e07281
tcp-port 5049
session-authorization
!
aaa server-group "MGMT_AUTH_SERVER"
auth-server 135.76.4.10
!
aaa authentication mgmt
server-group "MGMT_AUTH_SERVER"
enable
!
Is there a way how to take password from /etc/passwd ? I have around 300 users now ...
I have ArubaOS (MODEL: Aruba620), Version 6.1.3.1
Thank you so much!
Thank you and Best regards
Peter Mraz CCNP CCDP CCIP CERTIFIED
EVPN/AVPN Lead Engineer
AT&T Global Network Services Slovakia
EMEA Service Delivery
Tel.: +421 (0)2 502 10498
E-mail: pmraz at emea.att.com<mailto:pmraz at emea.att.com>
Time Zone: European Time (CET) = EST+6 hours = UTC+1 hour
Business hours: Mon - Fri 9am-5pm European Time (CET) = 3am-11am EST = 8am-4pm UTC
"This e-mail and any files transmitted with it are AT&T property, are confidential, and are intended solely for the use of the individual or entity to whom this e-mail is addressed. If you are not one of the named recipient(s) or otherwise have reason to believe that you have received this message in error, please notify the sender and delete this message immediately from your computer. Any other use, retention, dissemination, forwarding, printing, or copying of this e-mail is strictly prohibited."
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.shrubbery.net/pipermail/tac_plus/attachments/20130704/0598000b/attachment.html>
More information about the tac_plus
mailing list