Parameter
Description
Name
Enter a name for the server.
IP address
Enter the IP address of the TACACS server.
Auth Port
Enter a TCPIP port used by the server. The default port number is 49.
Shared Key
Enter a secret key of your choice to authenticate communication between the client and
the server.
Retype Key
Re-enter the shared key.
Timeout
Enter a number between 1 and 30 seconds to indicate the timeout period for requests.
The default value is 20 seconds.
Retry Count
Enter a number between 1 and 5 to indicate the maximum number of authentication attempts. The
default value is 3.
Dead time
Specify a dead time in minutes within the range of 1–1440 minutes. The default dead time interval
is 5 minutes.
Session
authorization
Enables or disables session authorization. When enabled, the optional authorization session is
turned on for the admin users. By default, session authorization is disabled.
Table 35:
TACACS Configuration Parameters
You can also add TACACS server by selecting the
New
option when configuring authentication parameters for
management users. For more information, see
Configuring Authentication Parameters for Management Users
l
CPPM Server
for AirGroup CoA—To configure a ClearPass Policy Manager server used for AirGroup CoA
(Change of Authorization), select the
CoA only
check box. The RADIUS server is automatically selected.
Parameter
Description
Name
Enter a name of the server.
Server
address
Enter the host name or IP address of the server.
Air Group CoA
port
Enter a port number for sending AirGroup CoA on a port different from the standard CoA port.
The default value is 5999.
Shared key
Enter a shared key for communicating with the external RADIUS server.
Retype key
Re-enter the shared key.
Table 36:
ClearPass Policy Manager Server Configuration Parameters for AirGroup CoA
4. Click
OK
.
The ClearPass Policy Manager server acts as a RADIUS server and asynchronously provides the AirGroup
parameters for the client device including shared user, role, and location.
Aruba Instant 6.5.0.0-4.3.0.0 | User Guide
Authentication and User Management |
159