9.3 ClearPass Policy Management and RADIUS Change of Authorization

Key Takeaways

  • Aruba ClearPass Policy Manager (CPPM) provides centralized, role-based network access control (NAC), evaluating context such as user identity, device profile, posture health, time, and location.

  • Device profiling dynamically identifies headless IoT endpoints through passive and active collectors (DHCP fingerprints, HTTP user agents, MAC OUIs), enabling tailored authorization without 802.1X supplicants.

  • ClearPass OnGuard performs endpoint posture assessment, checking antivirus definitions, OS patches, and disk encryption before admitting devices into corporate network segments.

  • RADIUS operates over UDP ports 1812 (Authentication/Authorization) and 1813 (Accounting), returning authorization parameters such as dynamic VLAN assignments and Aruba-User-Role Vendor-Specific Attributes (VSAs).

  • RADIUS Change of Authorization (CoA, RFC 5176) on UDP port 3799 enables ClearPass to initiate session modifications in real time, executing Disconnect Messages (DM) or CoA-Requests to elevate user roles after posture checks pass.

Last updated: October 2026

ClearPass Policy Management and RADIUS Change of Authorization

Quick Summary: Modern enterprise networks require identity-based access control rather than static port-based configurations. Aruba ClearPass Policy Manager (CPPM) delivers comprehensive Network Access Control (NAC) through dynamic role-based policies, automated device profiling, and endpoint posture evaluation. Using the RADIUS protocol (RFC 2865), ClearPass authenticates endpoints and dictates access privileges via dynamic VLANs and Aruba User Roles. Through RADIUS Change of Authorization (CoA, RFC 5176) on UDP port 3799, ClearPass dynamically modifies active client sessions in real time, enforcing posture remediation and rapid threat containment without requiring physical disconnection.


The Evolution of Enterprise Network Access Control

Traditional enterprise security relied heavily on static port configurations: assigning specific physical switch jacks to departmental VLANs. This legacy approach presents fatal design flaws in contemporary campus environments:

  • Operational Inflexibility: When employees move desks, network engineers must manually reconfigure switch ports.
  • The Proliferation of IoT: Modern campus facilities feature thousands of "headless" devices—IP surveillance cameras, smart LED lighting, smart TVs, medical telemetry sensors, and HVAC controllers—that lack interactive displays and cannot install client software.
  • Bring Your Own Device (BYOD): Employees and contractors connect personal smartphones, tablets, and unmanaged laptops that introduce untrusted software into the enterprise environment.

Role-Based Access Control (RBAC)

Aruba architecture replaces static port assignments with Role-Based Access Control (RBAC). Rather than basing trust on where a cable is plugged in, the network determines access rights based on who the user is, what device is connecting, when the connection occurs, and how healthy the endpoint is. Access policies are encapsulated into User Roles managed centrally by ClearPass Policy Manager.

The AAA Security Framework

ClearPass operates as the central engine for the AAA Framework:

+---------------------------------------------------------------------------------------------------------+
|                                      THE AAA SECURITY FRAMEWORK                                         |
|                                                                                                         |
|     [ 1. AUTHENTICATION ] ---------> "Who are you?"                                                     |
|                                      Validates credentials, 802.1X certificates, or MAC addresses.      |
|                                                                                                         |
|     [ 2. AUTHORIZATION ] -----------> "What are you allowed to do?"                                     |
|                                      Evaluates context; pushes dynamic VLANs, ACLs, and User Roles.     |
|                                                                                                         |
|     [ 3. ACCOUNTING ] --------------> "What did you do?"                                                |
|                                      Logs session start/stop, duration, byte counts, and audit trails.  |
+---------------------------------------------------------------------------------------------------------+

Device Profiling and Posture Assessment

ClearPass achieves contextual intelligence through two fundamental technologies: ClearPass Profiler and ClearPass OnGuard.

ClearPass Device Profiler

For devices that lack 802.1X supplicants (such as printers and badge readers), ClearPass performs device fingerprinting using passive and active telemetry collectors:

  • DHCP Snooping Helper: Inspects DHCP Option 55 (Parameter Request List) and Option 60 (Vendor Class Identifier) transmitted during address acquisition. A Zebra barcode printer requests completely different DHCP options than an Apple iPad or a Windows workstation.
  • HTTP User-Agent Strings: Parses web browser strings captured during captive portal redirection.
  • MAC OUI (Organizationally Unique Identifier): Analyzes the first 24 bits of the device MAC address to determine the hardware manufacturer (e.g., Axis Communications, HP Inc., Apple).
  • LLDP / CDP Discovery: Ingests Layer 2 neighbor discovery metadata forwarded by AOS-CX access switches, including device system descriptions, model numbers, and capabilities.
  • Active Network Probing: Executes targeted Nmap TCP/UDP port scans and SNMP queries to verify running operating systems and open network services.

Once profiled, ClearPass classifies the endpoint into a precise category (e.g., Device Category: Smart Device, OS: Apple iOS, Device Name: iPad) and applies tailored authorization rules.

ClearPass OnGuard: Endpoint Posture Assessment

Authenticating user credentials is not enough; the connecting device itself must be secure. ClearPass OnGuard performs pre-admission and post-admission posture assessment using either a persistent background agent or a dissolvable web agent:

  1. Health Verification: Inspects local endpoint security controls: verifying that the corporate antivirus engine is running, virus definition files are fewer than 3 days old, the local OS firewall is active, critical security patches are installed, and whole-disk encryption (BitLocker or FileVault) is active.
  2. Posture Token Assignment: ClearPass evaluates the health data and assigns a posture token: HEALTHY, QUARANTINE, or INFECTED.
  3. Phased Remediation Flow: If a laptop has outdated antivirus definitions, ClearPass places the device into a temporary Remediation Role. The user can only access the internal antivirus update server. Once definitions update and OnGuard re-evaluates the health state as healthy, ClearPass triggers a dynamic role change.

RADIUS Protocol Mechanics and Authorization Attributes

Communication between the AOS-CX access switch (acting as the Network Access Server, or NAS) and ClearPass Policy Manager (acting as the RADIUS Server) utilizes the standard Remote Authentication Dial-In User Service (RADIUS) protocol (RFC 2865 for Authentication/Authorization, RFC 2866 for Accounting).

Transport and Core Messages

  • Transport Protocol: RADIUS operates over UDP port 1812 for Authentication and Authorization, and UDP port 1813 for Accounting.
  • Standard Message Exchange:
    1. Access-Request: The switch forwards client credentials or EAP identity to ClearPass.
    2. Access-Challenge: ClearPass requests additional authentication handshakes (such as an EAP-TLS certificate exchange or multi-factor token).
    3. Access-Accept: ClearPass verifies credentials and returns network authorization parameters.
    4. Access-Reject: ClearPass denies network admission.

Key RADIUS Authorization Attributes

Inside the Access-Accept packet, ClearPass embeds specific attributes that instruct the AOS-CX switch on how to treat the client's traffic:

Attribute TypeAttribute Name & NumberFunction and Description
IETF StandardTunnel-Type (64)Set to value 13 (specifies VLAN encapsulation).
IETF StandardTunnel-Medium-Type (65)Set to value 6 (specifies 802 networks / Ethernet).
IETF StandardTunnel-Private-Group-Id (81)Specifies the dynamic VLAN ID (e.g., "20") or VLAN Name to which the switch port is assigned.
Aruba VSAAruba-User-Role (Vendor ID 14823, VSA 1)Specifies the name of a local or downloadable User Role on the AOS-CX switch, applying local ACLs, QoS, and policing.
IETF StandardSession-Timeout (27)Defines the maximum session duration in seconds before the client must re-authenticate.

RADIUS Change of Authorization (CoA - RFC 5176)

Traditional RADIUS is strictly client/NAS-initiated: the switch queries the server, the server responds, and the session remains frozen in that state until the client physically disconnects. RADIUS Change of Authorization (CoA), standardized under RFC 5176, revolutionizes this architecture by introducing server-initiated control.

+---------------------------------------------------------------------------------------------------------+
|                                 RADIUS CHANGE OF AUTHORIZATION (RFC 5176)                               |
|                                                                                                         |
|     [ ClearPass Policy Manager ] ------------ UDP Port 3799 ------------> [ AOS-CX Access Switch ]      |
|                                                                                                         |
|     1. DISCONNECT-REQUEST (DM):                                                                         |
|        Immediately tears down client session, resets port state, drops user from network.               |
|        (Switch responds with Disconnect-ACK or Disconnect-NAK).                                         |
|                                                                                                         |
|     2. CoA-REQUEST:                                                                                     |
|        Modifies active session parameters in real time (e.g., shifts role from Quarantine to Corporate)  |
|        WITHOUT disconnecting physical link or interrupting IP lease.                                    |
|        (Switch responds with CoA-ACK or CoA-NAK).                                                       |
+---------------------------------------------------------------------------------------------------------+

CoA Message Types

RFC 5176 defines two critical server-initiated operational messages, transmitted over UDP port 3799 (or legacy UDP port 1700):

  1. Disconnect-Request (Disconnect Message / DM):

    • Purpose: Forces the switch to terminate an active client session immediately.
    • Action: The switch clears the MAC forwarding table entry, tears down authentication state, and drops client traffic. If 802.1X is active, the client must restart the EAP exchange from the beginning.
    • Use Cases: Incident response isolation of a compromised device, administrative blacklisting, or handling guest session timeout.
    • Response: The switch returns a Disconnect-ACK upon successful termination, or Disconnect-NAK if the session could not be located.
  2. CoA-Request:

    • Purpose: Dynamically alters the authorization attributes of an active session without dropping the client's connection.
    • Action: The client maintains its physical link, Layer 2 state, and Layer 3 IP address. The switch updates the client's assigned User Role, VLAN, or ACL filters in real time.
    • Use Cases: Posture remediation elevation (transitioning from Quarantine-Role to Corporate-Role once OnGuard validates antivirus updates), captive portal post-authentication (shifting from unauthenticated Guest-Logon to authenticated Guest-Internet), or applying bandwidth throttling when a user exceeds daily quotas.
    • Response: The switch returns a CoA-ACK on success, or CoA-NAK if the requested attribute cannot be applied.

AOS-CX RADIUS and Dynamic Authorization Configuration

The following configuration establishes communication between an AOS-CX switch and ClearPass, enabling RADIUS authentication, accounting, and RFC 5176 Change of Authorization:

switch# configure terminal

! Step 1: Configure the ClearPass RADIUS Server and Enable Dynamic Authorization (CoA)
switch(config)# radius-server host 10.100.1.50 key plaintext ClearPassSecret2026
switch(config)# radius dyn-authorization enable
switch(config)# radius dyn-authorization client 10.100.1.50 secret-key plaintext ClearPassSecret2026

! Step 2: Create a RADIUS Server Group
switch(config)# aaa group server radius CPPM-CLUSTER
switch(config-sg-radius)# server 10.100.1.50
switch(config-sg-radius)# exit

! Step 3: Configure 802.1X Authentication to use the ClearPass Group
switch(config)# aaa authentication port-access dot1x authenticator radius server-group CPPM-CLUSTER
switch(config)# aaa authentication port-access dot1x authenticator enable

! Step 4: Configure Port-Access Client Roles for Posture Flow
switch(config)# port-access role Quarantine-Role
switch(config-pa-role)# vlan access 99
switch(config-pa-role)# exit
switch(config)# port-access role Corporate-Role
switch(config-pa-role)# vlan access 10
switch(config-pa-role)# exit

! Step 5: Enable 802.1X Authenticator on Access Port
switch(config)# interface 1/1/15
switch(config-if)# no routing
switch(config-if)# aaa authentication port-access dot1x authenticator enable
switch(config-if)# exit

Essential Verification Commands

CommandOutput and Operational Purpose
show radius-serverDisplays configured RADIUS servers, ports, and reachability.
show radius dyn-authorizationShows dynamic authorization (CoA) status and counters for Disconnect-Requests, CoA-Requests, ACKs, and NAKs.
show port-access clientsDisplays active authenticated clients, MAC addresses, switch ports, and assigned roles.
show port-access clients detailProvides deep telemetry for a specific client: EAP method, VLAN ID, user role, and session timers.
show port-access roleLists all locally configured and dynamically downloaded user roles and bound policies.

Common Exam Traps

  • Transport Port Numbers: RADIUS Authentication runs over UDP 1812, Accounting over UDP 1813, and RADIUS CoA over UDP 3799. Notice that all three use UDP, contrasting sharply with TACACS+ which runs over TCP port 49.
  • Forgetting dynamic authorization: On AOS-CX switches, radius-server host <ip> enables standard authentication only. To accept CoA messages on UDP 3799 you must enable radius dyn-authorization enable and define the sending server with radius dyn-authorization client <ip> secret-key ....
  • Disconnect vs. CoA Distinction: A common exam question tests which message type changes an active user role without disrupting link state. A Disconnect-Request drops the link/session, whereas a CoA-Request modifies session attributes in-place without disconnecting.
Loading diagram...
ClearPass Authentication, Posture Assessment, and RADIUS CoA Flow
Test Your Knowledge

Which set of profiling collectors does Aruba ClearPass Policy Manager utilize to dynamically fingerprint and categorize headless IoT devices that do not support 802.1X authentication?

A

IPsec security association negotiations and spanning tree BPDU priority fields

B

DNSSEC public key exchanges together with NTP stratum level synchronization data

C

DHCP fingerprints (options 55/60), HTTP User-Agent, MAC OUI, and LLDP/CDP data

D

BGP routing table advertisements combined with OSPF Link State Request summaries

Test Your Knowledge

What is the primary operational distinction between a RADIUS Disconnect-Request (DM) and a RADIUS CoA-Request under RFC 5176?

A

A Disconnect-Request is sent over TCP port 49, whereas a CoA-Request is sent over UDP port 1812

B

A Disconnect-Request ends the session, whereas a CoA-Request changes session attributes in place

C

A Disconnect-Request changes the client's VLAN in real time, whereas a CoA-Request reboots the switch

D

A Disconnect-Request applies only to wireless controllers, whereas a CoA-Request applies only to switches

Test Your Knowledge

When configuring dynamic VLAN assignment from Aruba ClearPass Policy Manager to an AOS-CX switch using standard IETF RADIUS attributes, which three attributes must be returned in the RADIUS Access-Accept message?

A

User-Name = VLAN name, Filter-Id = VLAN ID, and Class = the dynamic user role name

B

Service-Type = Framed (2), Login-IP-Host = VLAN gateway, and Acct-Interim-Interval = VLAN ID

C

NAS-Identifier = switch name, Calling-Station-Id = client MAC, and Framed-IP-Address = VLAN SVI

D

Tunnel-Type = VLAN (13), Tunnel-Medium-Type = 802 (6), and Tunnel-Private-Group-Id = VLAN ID

Sections you finish are checked off in the contents.