When troubleshooting downloadable user roles (DUR) between Aruba CX switches and ClearPass, it is crucial to verify the Trust Anchor profile on the switch. The Trust Anchor profile contains the certificates and keys that allow secure communication and authentication with ClearPass, ensuring the switch can validate the RADIUS server and downloaded user role information.
SNMP community string (Option A) is unrelated to DUR.
User-role configuration (Option B) is important but verifying trust anchor ensures secure role downloads.
HTTPS client certificate (Option C) is not typically part of DUR authentication.
Therefore, the Trust Anchor profile must be verified.
[References:, , Aruba ClearPass and CX Switch Integration Guide, , ArubaOS-CX Security and Authentication Documentation, , Aruba ClearPass Downloadable User Roles Best Practices]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit