Controllerless Networks

last person joined: 2 days ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

IAP225 - 6.4.0.0-4.1.0.1 Dynamic Radius Proxy didn't work

This thread has been viewed 0 times
  • 1.  IAP225 - 6.4.0.0-4.1.0.1 Dynamic Radius Proxy didn't work

    EMPLOYEE
    Posted Aug 08, 2014 05:08 PM

    Part question and part comment, but wasted a good few hours yesterday with a deployment of IAP225 on latest code (4.1.0.1) with things not quite working.

     

    Turns out that when I had dynamic radius proxy enabled it didn't work.  As soon as I disabled it, things worked fine.

     

    Has anyone else come acros this?



  • 2.  RE: IAP225 - 6.4.0.0-4.1.0.1 Dynamic Radius Proxy didn't work

    EMPLOYEE
    Posted Aug 08, 2014 05:22 PM

    Michael_Clarke,

     

    When you turned it on, did ANYTHING get to the radius server?  Please be specific about did not work...

     



  • 3.  RE: IAP225 - 6.4.0.0-4.1.0.1 Dynamic Radius Proxy didn't work

    EMPLOYEE
    Posted Aug 08, 2014 05:36 PM
    Yes, everything was getting to the clearpass fine. It was the responses that weren't getting back to the VC. I did a capture on the clearpass and they were being sent.

    Routing was fine cause clearpass could ping the VC.

    On the ap, the requests were just timing out.


  • 4.  RE: IAP225 - 6.4.0.0-4.1.0.1 Dynamic Radius Proxy didn't work

    EMPLOYEE
    Posted Aug 08, 2014 05:38 PM

    Did you do a capture at the AP to see if it was being seen at the APs interface?  Is the IAP on the same VLAN as Clearpass?  Does the IAP have the correct subnet mask?



  • 5.  RE: IAP225 - 6.4.0.0-4.1.0.1 Dynamic Radius Proxy didn't work

    EMPLOYEE
    Posted Aug 08, 2014 05:52 PM

    I didn't get a chance to capture at the ap..... Under pressure to get it working.

     

    IAP and clearpass on different subnets, but they have the correct mask.

     

    Basically, it's like this.

    • In clearpass I changed the network device to be the iap subnet, rather than just the VC Address.
    • Disabled dynamic radius proxy.
    • Boom. Everything working.

     

     



  • 6.  RE: IAP225 - 6.4.0.0-4.1.0.1 Dynamic Radius Proxy didn't work

    Posted Aug 11, 2014 02:26 PM

    When I updated to 4.1.0. 1 I had the same problem. The fix I found was to reboot the current master and let instant elect a new one. Once I did that Radius Proxy started working again.

     

    To answer the question asked, in MY case No traffic was getting to the radius server until I rebooted the current master.

     

    Alex