Controllerless Networks

last person joined: yesterday 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

CoA with Instants

This thread has been viewed 2 times
  • 1.  CoA with Instants

    Posted Oct 08, 2014 11:54 AM

    We are running latest CPPM code 6.4.1.30651 and Aruba Instant code 6.4.2.0

    We are trying to implement CoA to force clients to re-authenticate after a certain

    time period.

    The problem is we see this working with Aruba controller code but NOT with instant.

    Any ideas?

    cheers

    Pete

     



  • 2.  RE: CoA with Instants

    Posted Oct 08, 2014 12:16 PM

    From ClearPass you can set an radius attribute with session-timeout on the enforcement profile

     

    2014-10-08 12_17_43-Chrome Remote Desktop.png



  • 3.  RE: CoA with Instants

    EMPLOYEE
    Posted Oct 08, 2014 12:18 PM

    If you use session-timeout, make sure you have RADIUS accounting enabled.



  • 4.  RE: CoA with Instants

    Posted Oct 08, 2014 12:19 PM

    Valid point by cappalli..



  • 5.  RE: CoA with Instants

    Posted Oct 08, 2014 12:23 PM

    Thanks for reply.

    We have accounting enabled and all works fine, but we have to issue a CoA at specific times

    for the solution to work.

    My question is does CoA work between Instants and CPPM?

    cheers

    pete

     

    p.s. works great with controller



  • 6.  RE: CoA with Instants

    EMPLOYEE
    Posted Oct 08, 2014 12:33 PM

    Yes, CoA should work with Instant. Can you try to manually issue a CoA from access tracker and see if it gives you an error?



  • 7.  RE: CoA with Instants

    Posted Oct 08, 2014 12:35 PM

    already tried that same result.

     



  • 8.  RE: CoA with Instants

    EMPLOYEE
    Posted Oct 08, 2014 12:37 PM
    What does it say in ClearPass when you do it?

    Successful, administratively prohibited or session context not found?


  • 9.  RE: CoA with Instants

    Posted Oct 08, 2014 12:41 PM

    Tim,

    extract from CPPM Access Tracker,

    :-

    Date and Time Oct 08, 2014 13:10:22 BST
    Application Name Policy Manager
    RADIUS CoA Action Type Disconnect
    RADIUS CoA Action Name [Aruba Terminate Session]
    Status Code 0
    Status Message Radius [Aruba Terminate Session] failed for client 00224360da63
    RADIUS CoA Attributes Calling-Station-Id = 00224360da63



  • 10.  RE: CoA with Instants

    Posted Oct 08, 2014 12:55 PM

    yes that is enabled



  • 11.  RE: CoA with Instants

    Posted Oct 08, 2014 02:23 PM

    Tim,

    just to let you know we are sourcing the radius traffic from the DRP IP address

    not from the VC. All radius traffic works fine with this but i am wondering if the

    CoA works with this.

     



  • 12.  RE: CoA with Instants

    EMPLOYEE
    Posted Oct 08, 2014 12:52 PM

    Do you have RFC 3576 enabled in your RADIUS server configuration in Instant?

     

    rfc3576-instant.png