Downloading an undefined role from CPPM to Controller

Requirement:
In order to provide per-user level access, user roles can be created when a user has been successfully authenticated.During the configuration of a remote access policy, administrator can define a role that should be assigned to the user after successful authentication. If the Role is not defined in the Controller, Role can not be mapped to the User hence we need a solution where we can download a relevant Role from the server.
Solution:
In RADIUS authentication, when Server (CPPM) successfully authenticates a user, the user is assigned a role ( role name) by the Server (CPPM) and if the role is not defined on the controller, the role attributes can also be automatically downloaded from CPPM.
This feature supports roles obtained by the following authentication methods:
802.1x (wireless and wired users)
MAC authentication
Captive Portal
CPPM does not perform any error checking to confirm accuracy of the role definition (policy mapped to the Role). Controller will validate the Policy before downloading.
Configuration:
How to enable :
1. Navigate to the Configuration > Security > Authentication > AAA Profiles.
2. Select an AAA profile.
3. Check the Download Role from CPPM check box to enable role download.
Providing CPPM credentials:
It is mandatory ( From CPPM 6.4 ) to specify CPPM credentials for downloading the Role
Configuring CPPM :
A Role can be defined and mapped trough an Enforcement profile as shown bellow.
We should select “ Aruba Downloadable Role Enforcement” from Template dropdown list.
Add Aruba controller IP in the Device list ( First create a group, Ex “My_Devices” and add the IP address to that group)
Defining and mapping the Policy to the Role :
Define a policy ( ACL) by selecting type of ACL (Stateless ACL/Session ACL/Ethertype)
Add the policy to the Role ( Ex Test_policy)
Add the VLAN and CP profile as per the requirement.
Summary of Enforcement Profile :
Define and Enforcement Policy :
A policy/ Rules required to pickup this Enforcement profile,
Create a new enforcement policy and define a condition for picking the Profile
Defining a Service :
Finally we have to define a Service to handle this Authentication
Define a service by selecting an appropriate template ( Ex Aruba 802.1x Wireless/ Aruba 802.1x Wired/Aruba Guest  etc..)
Select desired type of Auth types ( EAP-PEAP, MSCHAP V2 etc..)
Select the Enforcement profile
Verification
Testing :
On successful Authentication, CPPM will push the Role along with the policy to the Controller as shown below.
Role is being downloaded to the Controller :
Role is downloaded and a policy is created :

Requirement:
In order to provide per-user level access, user roles can be created when a user has been successfully authenticated.During the configuration of a remote access policy, administrator can define a role that should be assigned to the user after successful authentication. If the Role is not defined in the Controller, Role can not be mapped to the User hence we need a solution where we can download a relevant Role from the server.
Solution:
In RADIUS authentication, when Server (CPPM) successfully authenticates a user, the user is assigned a role ( role name) by the Server (CPPM) and if the role is not defined on the controller, the role attributes can also be automatically downloaded from CPPM.
This feature supports roles obtained by the following authentication methods:
802.1x (wireless and wired users)
MAC authentication
Captive Portal
CPPM does not perform any error checking to confirm accuracy of the role definition (policy mapped to the Role). Controller will validate the Policy before downloading.
Configuration:
How to enable :
1. Navigate to the Configuration > Security > Authentication > AAA Profiles.
2. Select an AAA profile.
3. Check the Download Role from CPPM check box to enable role download.
Providing CPPM credentials:
It is mandatory ( From CPPM 6.4 ) to specify CPPM credentials for downloading the Role
Configuring CPPM :
A Role can be defined and mapped trough an Enforcement profile as shown bellow.
We should select “ Aruba Downloadable Role Enforcement” from Template dropdown list.
Add Aruba controller IP in the Device list ( First create a group, Ex “My_Devices” and add the IP address to that group)
Defining and mapping the Policy to the Role :
Define a policy ( ACL) by selecting type of ACL (Stateless ACL/Session ACL/Ethertype)
Add the policy to the Role ( Ex Test_policy)
Add the VLAN and CP profile as per the requirement.
Summary of Enforcement Profile :
Define and Enforcement Policy :
A policy/ Rules required to pickup this Enforcement profile,
Create a new enforcement policy and define a condition for picking the Profile
Defining a Service :
Finally we have to define a Service to handle this Authentication
Define a service by selecting an appropriate template ( Ex Aruba 802.1x Wireless/ Aruba 802.1x Wired/Aruba Guest  etc..)
Select desired type of Auth types ( EAP-PEAP, MSCHAP V2 etc..)
Select the Enforcement profile
Verification
Testing :
On successful Authentication, CPPM will push the Role along with the policy to the Controller as shown below.
Role is being downloaded to the Controller :
Role is downloaded and a policy is created :

Similar Messages

  • Remove Domain Controller role from Exchange 2010 Server

    Hi team,
    There is a client with Domain Controller (2008 R2) running together with Exchange Server 2010 SP3. However there were some huge problems with Exchange and DC therefore since the best practice is to keep those roles seperately, they are in need of doing so.
    Can someone please suggest me the best approach? The server they use right now is with 16GB therefore whatever done, Exchange should be on that machine and DC on the other 6GB.
    Option 01.
    Both Exchange and DC are together
    Install new Exchange on a temporary Server and move everything make that Exchange server the only working primary
    Remove exchange from the DC server
    Promote new Additional DC and promote it with FSMO and make primary
    Demote the old DC from the 16GB server
    Install Exchange again on the 16GB server and move everything from the temporary server
    Or Option 02
    Add new additionall Domain Controller server and make it primary with GC and FSMO
    Run dcpromo to demote the old Domain controller role from where the Exchange Server too is installed
    Once DC role is removed from the exchange server, set up DNS and perform a restart, so Exchange will identify the new GC and domain controller
    Live happily ever after
    Thank You,
    Cheers!!

    Adding/Removing the DC-Role while Exchange is installed, is not supported so forget about your Option 2.
    Here's what I would do:
    1. Install a new GC/DC (move FSMO etc)
    2. Install a new temporary server for Exchange and move everthing over
    3. Decomission the old Exchange Server
    4. Demote the old Domain Controller
    5. Install Exchange on a newly freshly installed OS and move everything over from your temp server
    Martina Miskovic

  • How can download the roles from one system and upload them into another  ??

    Do anyone have the solution ..... ......it  very  important.

    Hi,
    Visit [Role Maintenance Functions|http://help.sap.com/saphelp_nw04/helpdata/en/e4/15e48efd6c11d296430000e82de14a/content.htm] in section Download/Upload.
    To avoid inconsistencies, all roles from which a role is derived are also downloaded. When you download composite roles, all the roles which they contain are also downloaded.
    When you upload a role, all role data, including authorization data is uploaded from a file into the SAP system. The user assignments for the role and the generated profiles for the role are exceptions in this case. You must therefore regenerate the authorization profiles after the upload.
    Mass Download:
    Save several roles on the PC.
    You can choose on the selection screen whether you:
         Also want to transport the single roles contained in the selected composite roles (Customizing switch ADD_COMPOSITE_ROLES in table SSM_CUST)
         Also want to transport the generated profiles for all single roles (PROFILE_TRANSPORT in table PRGN_CUST)
    You can define the default setting for both options using the value in the Customizing switch. If you explicitly set a switch to NO, the option in question on the selection screen is not active. Otherwise, it is active.
    Regards,
    Srilatha.

  • Download MDM roles from repository

    Hi,
    How do I download roles from MDM repostories with their respective functions and tables and fields into an spread sheet.
    Rakesh

    Are you SQL savvy?  Take a look at the database schema MDM creates (on Oracle/SQL Server - whatever you've used).
    In the schema named "YourRepository_M000", look for the set of tables starting with A2i_CM_ROLE...
    It's pretty easy to generate a simple report of Roles vs Users.  You'll need get a a little more creative to get those to show role details (function/table/field), but the data is all right there.
    Here's a start...
    SELECT r.rolename, r.description "Role Description", u.username, u.fullname, u.description "User Description", u.useremails
       FROM YourRepositoryName_M000.A2i_CM_ROLES r, YourRepositoryName_M000.A2i_CM_USERS u, YourRepositoryName_M000.A2i_CM_USER_ROLES ur
      WHERE r.roleid = ur.roleid
        AND u.userid = ur.userid
      ORDER BY 1, 2

  • Error while uploading roles from quality to production

    Dear friends,
    I have to upload roles from quality to production.
    I have downloaded it from qualtiy but while uploading to production it is giving me an error "File does not contain valid data".
    Can anybody tell me what could be the problem and how to resolve it.
    Thanks in advance
    regards
    Nirgun

    HI matore,
    the best way is to transport the roles from DEV to QA and then to production as julius suggested
    are you trying for mass down load are single role
    Mass download
    go to PFCG >> utilities>> Mass download>> select all the roles which you want to move it to production
    and execute save it on desktop
    now go to production system>> go to PFCG>>in menu click on roles>>click on upload>>select the file which is saved in desktop and click ok
    mass generation of roles
    in the menu click on utilities>>mass generation>>give the role names with you have uploaded and click on execute select all click on genetate button
    download a single role
    go to PFCG>>in the menu click on role>>click on down load and save it on desktop
    now go to production system>> go to PFCG>>in menu click on roles>>click on upload>>select the file and click ok
    now you needs to manully generate the role
    do the user comparison
    hope this helps
    thanks
    kishore

  • Integrate GRC 10.1 with CUA and how to import roles from CUA & Child systems into GRC for provisioning

    Hello,
    I am trying to integrate CUA into our GRC 10.1 system through the below steps and so far I have completed the below steps following SAP Notes 1680108 and 1616121:
    1. Connected CUABOX to GRCBOX like a plug-in system.
    2. Updated CUA Global System and CUA Model Distribution in Maintain CUA settings under User Provisioning.
    3. Next I am trying to import the roles from CUA(CUABOX) into GRC(GRCBOX) to be able to provision roles in CUA Child Systems(ECCBOX).
    After reading few discussions in SCN, I have figured that we have to download a template in Role Import and populate it accordingly to upload the CUA child system roles into GRC system for provisioning in CUA Child Systems.
    Unfortunately, this template has multiple fields and I am unable to determine the fields that should be populated as CUA Global System and CUA Child System to import into GRC. Also, when we upload CUA Child System Roles template what selections should be made in Role Import window.
    Any help in this regard is very helpful.
    Thank you,
    Pawan

    Hi Alessandro,
    I have "Create user if does not exist" setting checked for both change action and assign role action and also have CUA enabled. Here is the list of steps that I am performing:
    1. Create an access request for new account, T-CUA_CHILD and select a role from a child system ECC Z_ECC_ROLE_IN_CHILD_SYSTEM.
    2. Approvals provided to assign the ECC role.
    3. I see the following in GRFNMW_DBGMONITOR_WD.
               Auto provisioning activity at end of request at Path GRAC_DEFAULT_PATH and Stage              GRAC_SECURITY
                   New User:T-CUA_CHILD created in System(s): ECC (created without role assignments)
                   T-CUA_CHILD User does not exist in target system CUA
    GRC created an account without role assignment in ECC but also throwed me an error that the user does not exist in CUA.
    However, if I select roles from both CUA and ECC it creates the account in both systems with the selected role assignments.
    So I am wondering if there is way to provide CUA access to users by default for new account requests types. I have tried setting up default roles for CUA but it does not assign the roles by default until I select the CUA system.
    Thank you for your help!
    Pawan

  • How do I overcome the Failed Downloads for Instant Movies from the Adobe Server?

    I have a Windows 8.1 PC , Premiere Elements ver. 12, and I have a  dedicated DSL for computer only. In my best efforts, even when disabling  McAfee completely, I have had almost 4 days of frustration trying to  download an Instant Movie from the online content server. At times the  DL works, slowly, then it pauses, sometimes the DL reverses the count  and I lose 10mb and it resumes (I have never seen that before). Most  frustrating is when the DL is nearly complete and the message pops up  that I need to check my connection as the download has failed. I have  1.6TB disc space, and no restrictions in place at my end. I tried from 2  of the PCs, both Win 8.1. I have tried at all hours of the day for  traffic on the server, but that doesn't seem to matter. I have attempted the Secret Agent file DL at best 10x.  Is there a  setting I need to change to receive this content, or go to a different  site where I can directly access this content?
    I have purchased Three PE 12 programs for 3 replacement PCs and I need some real direction.
    Thank you, Jerry

    Jerry W B
    There will be those that report Content download of a few minutes. Although we are happy for them, many have found that this is not usually the case. Download of the Premiere Elements 11 and 12 Content download is often a slow process which demands a lot of patience whether the download be "Download Now" or "Download All".  Just two of the factors in this situation are the Internet Speed/Status and the status of the Adobe Server. Many times it is time of the day.
    http://www.atr935.blogspot.com/2013/05/pe11-no-content-disc-content-downloads.html
    http://atr935.blogspot.com/2013/12/pe12-content-download-considerations.html
    I have DSL Service on the east coast of the USA. It is now about 6 pm Saturday February 22, 2014.
    I right clicked the blue ban at the top right corner of the Instant Movie thumbnail for the Secret Agent theme. I selected Download Now to download just that one Instant Movie theme.
    a. The file size was given as 75.8 MB, not 118.7 MB. It took 11 minutes and 19 seconds to download that Instant Movie.
    I checked the download on two different computers, one Windows 7 64 bit and the other Windows 8.1 64 bit. The Instant Movie Secret Agent had a file size of 75.8 MB according to the download pop up in the opened project.
    b. If you are talking days for this download, then I would first check with your Internet provider. There is no other place for these downloads except from within the program. And, when you do get them, I would encourage you to save them as per my blog posts on this topic to avoid having to go through an labored downloading processes again.
    Do you find the downloading of Content to be the same for all the other categories requiring this type of download, not just Instant Movies?
    Please review and update us on your progress.
    Thank you.
    ATR
    Add On...Although you did say that you disabled McAfee, be advised that McAfee's recent update(s) have created some serious problems for Premiere Elements. So, I would re-evaluate McAfee's possible role in all this along with the firewalls settings.

  • What is the best practice and Microsoft best recommended procedure of placing "FSMO Roles on Primary Domain Controller (PDC) and Additional Domain Controller (ADC)"??

    Hi,
    I have Windows Server 2008 Enterprise  and have
    2 Domain Controllers in my Company:
    Primary Domain Controller (PDC)
    Additional Domain Controller (ADC)
    My (PDC) was down due to Hardware failure, but somehow I got a chance to get it up and transferred
    (5) FSMO Roles from (PDC) to (ADC).
    Now my (PDC) is rectified and UP with same configurations and settings.  (I did not install new OS or Domain Controller in existing PDC Server).
    Finally I want it to move back the (FSMO Roles) from
    (ADC) to (PDC) to get UP and operational my (PDC) as Primary. 
    (Before Disaster my PDC had 5 FSMO Roles).
    Here I want to know the best practice and Microsoft best recommended procedure for the placement of “FSMO Roles both on (PDC) and (ADC)” ?
    In case if Primary (DC) fails then automatically other Additional (DC) should take care without any problem in live environment.
    Example like (FSMO Roles Distribution between both Servers) should be……. ???
    Primary Domain Controller (PDC) Should contains:????
    Schema Master
    Domain Naming Master
    Additional Domain Controller (ADC) Should contains:????
    RID
    PDC Emulator
    Infrastructure Master
    Please let me know the best practice and Microsoft best recommended procedure for the placement of “FSMO Roles.
    I will be waiting for your valuable comments.
    Regards,
    Muhammad Daud

    Here I want to know the best practice
    and Microsoft best recommended procedure for the placement of “FSMO Roles both on (PDC) and (ADC)” ?
    There is a good article I would like to share with you:http://oreilly.com/pub/a/windows/2004/06/15/fsmo.html
    For me, I do not really see a need to have FSMO roles on multiple servers in your case. I would recommend making it simple and have a single DC holding all the FSMO roles.
    In case if
    Primary (DC) fails then automatically other Additional (DC) should take care without any problem in live environment.
    No. This is not true. Each FSMO role is unique and if a DC fails, FSMO roles will not be automatically transferred.
    There is two approaches that can be followed when an FSMO roles holder is down:
    If the DC can be recovered quickly then I would recommend taking no action
    If the DC will be down for a long time or cannot be recovered then I would recommend that you size FSMO roles and do a metadata cleanup
    Attention! For (2) the old FSMO holder should never be up and online again if the FSMO roles were sized. Otherwise, your AD may be facing huge impacts and side effects.
    This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
    Get Active Directory User Last Logon
    Create an Active Directory test domain similar to the production one
    Management of test accounts in an Active Directory production domain - Part I
    Management of test accounts in an Active Directory production domain - Part II
    Management of test accounts in an Active Directory production domain - Part III
    Reset Active Directory user password

  • Can u upload Roles from 4.6C to ECC 6.0

    Hi all,
    1. Can we upload some roles from 4.6C system to an ECC 6.0 system? Will it accept and work properly?
    Regards
    Senthil

    >
    Hillary Hoffman wrote:
    > Can you tell what transaction or process you use to upload?
    Same as for the download, PFCG. Do mind the character set ('parameter' pulldown menu at the bottom of file save/open dialog box), they have to be the same on both sides.

  • Transporting roles from sandbox to a DEV environment

    Hi all,
    We have some external consultants who have been developing/modifying roles in a sandbox.  They have put in a lot of work into this effort and do no want to re-create these roles in the DEV environment.  Does SAP best practice allow us to transport these roles from the SANDBOX to the DEV ?  or do we insist that the roles be re-created in the DEV box ?  Will there be maintenance issues down the road if we do the tranport ?
    Thanks,
    Denis Louis

    Yes, you can download them to your desktop and upload them to the DEV...
    PFCG -> Role -> Download and Upload
    Regards
    Juan

  • Transferring FSMO roles from 2003 DC to 2012 R2 DC - and how exchange will react.

    Hi Folks,
    I want to transfer the FSMO roles from our current 'PDC' which is server 2003 to a new Server 2012 R2 DC. Im fine with the steps i have to perform to accomplish this but as always, the wildcard is how my exchange 2007 server will react to such a change. 
    Does anyone have any insight as to whether exchange will just pick up the new 'PDC' without any issues? i am going to leave the domain functional level at 2003 until i am able to migrate to exchange 2013.
    thanks.
    Colin Stewart

    your active directory is a database, if exchange 2007 is working with the current functional level it will work after the roles are moved, the active directory database does not change when you move it to a newer domain controller, it doesn't really change
    when you raise the functional level, it changed when you run adprep for a application like exchange 2007, so if it runs now moving roles to new DC will not change that  ,raising your functional level will give you more features in AD like recycle
    bin which is nice.

  • I am unable to open raw files from my Canon T1i in Adobe Camera Raw of my version CS3 of Photoshop.  I have tried to update my ACR by downloading version 4.6 from the Adobe website but I am still unable to open raw files, just JPEG.  Is there a way to use

    I am unable to open raw files taken on my Canon Rebel T1i in my version of Photoshop CS3.  When I import raw files into Bridge they come up as patches with CR2 on them and when clicked on, a notice comes up stating that Photoshop does not recognize these files.  I tried to update my Adobe Camera Raw by downloading version 4.6 from the Adobe Website, but when I clicked on the plus-in, I got another message that Photoshop does not recognize this file.  I spoke with a representative from Canon who said that I could not update CS3 and that I should subscribe to the Cloud.  I would prefer to use my CS3, if possible.  Can anyone advise me what to do?

    The T1i was first supported by Camera Raw 5.4 which is only compatible with CS4 and later
    Camera Raw plug-in | Supported cameras
    Camera Raw-compatible Adobe applications
    Some options:
    Upgrade to CS6
    Join the Cloud
    Download the free Adobe DNG converter, convert all T1i Raw files to DNGs then edit the DNGs in CS3
    Camera raw, DNG | Adobe Photoshop CC

  • Iv downloaded the 0845 wizard from the App Store. Registered my details and it has been working. But for some reason it won't let me log in and keep saying failed every time I try to use it. Iv deleted and re-downloaded the app and it still says the same?

    Iv downloaded the 0845 wizard from the App Store. Registered my details and it has been working. But for some reason it won't let me log in and keep saying failed every time I try to use it. Iv deleted and re-downloaded the app and it still says the same?

    I would say to start by looking on their web site... unfortunately, that appears to be dead.
    Based on the horrible ratings on the App Store (1 star for the current version), I'm not surprised it doesn't work well.

  • When I download a new app from the App Store it does not show up on my home screen but I can find it in my settings but out from it says no data

    When I download a new app from App Store and press open when it's complete, it won't do anything, and when I look on my home screens it's nowhere to be found but if I go to settings and look under icloud and usage, I can find them but out from it says no data. I have tried deleting them and reinstalling but that's no working either... Please help me.. Thank you very much:)

    Try resetting the phone. Push both the home and lock button at the same time until it goes off. Keep them pushed until the Apple logo come up...
    Also, try deleting the app and downloading it again.

  • I downloaded a WMA audiobook from library using Overdrive. It shows up on my Itunes listing of Audiobooks on my Ipod, but on the actual Ipod it only shows up on Playlists. How do I get it to show up under Audiobooks?

    I downloaded a WMA audiobook from library using Overdrive. It shows up on my Itunes listing of Audiobooks on my Ipod, but on the actual Ipod it only shows up on Playlists.  It is marked as an audiobook in Options | Media Kind.  It is also marked to Remeber Position, but it does not do that. How do I get it to show up under Audiobooks and remember the position?  I have a 4th Gen Ipod running Ios5

    Check out the instructions for a work around on this post: https://discussions.apple.com/message/18702732#18702732
    This worked for me.  I would like to see Apple fix this issue, as it isn't very fun to have to do this for every downloaded book.

Maybe you are looking for

  • How can I upload my CS5.5 programs to my new laptop without a CD player

    HELP!!! I purchased CS 5.5 illustrator/photoshop/acrobat in CD version.  I now have a new laptop which does not have a cd player.  How can I upload these programs? Adobe.com no longer has CS5 for downloads. I really need these programs on my new lapt

  • Zen micro, how do i delete everythi

    i want to delete all the tracks i put on it and start from scratch.is there a way to do this without going one by one? i tried deleting the playlist, deleting the genre (only had one on there so far) but the music is still there when i go to "all tra

  • Convince me

    I am on the fence. I've never owned a Mac before, but realized last semester that it is once again time to own a laptop, and so I have begun to look. I cannot escape the idea that being able to not only use the highly regarded OSX Leopard as well as

  • Cant install on Internal Hard Disk need help . . .

    i have the latest powerbook, and i have my treo hooked up to it, after i installed bootcamp and i had to partition the hard drive, i am no longer able to connect to the palm, and i cant install anything, the macintosh HD is not available for instalat

  • 2008R2 Virtual machine shutting down unexpected on Hyper-V 2012 server

    I have a problem where one of my 2008 R2 virtual servers are shutting down unexpected every Friday at more or less the same time. This has happen 2 Fridays in a row now and the time is 13:01:30 and 13:01:10. I did some investigation on the event view