Controllerless Networks

last person joined: 2 days ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

iap-93 rfc-3576

This thread has been viewed 2 times
  • 1.  iap-93 rfc-3576

    Posted Oct 01, 2012 11:31 AM

    hy all,

     

    i was wondering how the ipa-93 compliance of rfc-3576 works ?

     

    i'm currently using packetfence and it tries to access my iap-93 on port UDP/3799.

     

    any clues ?

     

    Regards,

     

    Xinity



  • 2.  RE: iap-93 rfc-3576

    EMPLOYEE
    Posted Oct 01, 2012 11:54 AM

    Xinity,

     

    Do you have your packetfence setup as a radius server with RFC3576 enabled on your IAP virtual controller?

     

    3576.png



  • 3.  RE: iap-93 rfc-3576

    Posted Oct 01, 2012 12:13 PM

    hy,

     

    packetfence has a configuration template for all Aruba devices, which is what i have used.

    i don't remember setting anything about NAS-Identifier in packetfence (which uses freeradius) .

     

    i my case:

    - NAS IP address -->  IP of my VC (@range.7) my access point is using @range.8

    - NAS Identifier --> [blank]

     

     i forgot to mention that i my Access point, i've enabled RFC-3576

     

    Thanks for your help,

     

    Regards,

     

    Xinity

     

     



  • 4.  RE: iap-93 rfc-3576

    EMPLOYEE
    Posted Oct 01, 2012 12:51 PM

    Xinity,

     

    Theoretically that should work, but I do not know if Packetfence specifically was tested...

     



  • 5.  RE: iap-93 rfc-3576

    Posted Oct 02, 2012 03:26 AM

    thanks anyway,

     

    i'll dig in to see how to make this work :)

     

    Regards,

     

    Xinity



  • 6.  RE: iap-93 rfc-3576

    Posted Oct 02, 2012 11:35 AM

    Can you explain how the iap-93 should handle CoA request ?

    it is using a specific network port (tcp/udp ?)

     

    i've read about the RFC3576.

    the RFC is related to

     

    I°) Dynamic Authorization Extensions to Radius:

    "The NAS responds to a Disconnect-Request packet sent by a RADIUS server with a Disconnect-ACK if all associated session context is discarded and the user session is no longer connected, or a Disconnect-NAK, if the NAS was unable to disconnect the session and discard all associated session context"

     

    II°) Change-of-Authorization-Messages (CoA):

    "The NAS responds to a CoA-Request sent by a RADIUS server with a CoA-ACK if the NAS is able to successfully change the authorizations for the user session, or a CoA-NAK if the Request is unsuccessful."

     

    which is available on an IAP-93 arubaOS 6.1.3.1-3.0.0.2_34479 ?

    how to use this/these feature(s) ?

     

    Thanks for your precious help,

     

    Regards,

     

    Xinity



  • 7.  RE: iap-93 rfc-3576

    Posted Jan 29, 2013 08:08 AM

    Hello,

     

    did you get Packetfence work with your IAP?

     

    I tried it to with an Aruba IAP 135 but I didn´t get it work, yet.

     

     



  • 8.  RE: iap-93 rfc-3576

    Posted Jan 29, 2013 08:26 AM

    Hy,

     

    I did make my IAP-93 work with packetfence, except for the CoA, i'm still fighting :(

    do you need any help ?



  • 9.  RE: iap-93 rfc-3576

    Posted Jan 29, 2013 09:22 AM

    yes I need help.

    What have you configure on the IAP and what did you configure at the packetfence site?

     

    I tried it but it won´t work.

     

     

     



  • 10.  RE: iap-93 rfc-3576

    Posted Jan 29, 2013 10:03 AM

    Ok I tried it so mutch but it didn´t work.

     

    I configure it like in this link:
    http://www.packetfence.org/bugs//bug_view_advanced_page.php?bug_id=1618

     

    but it won´t work.

     

    The Packetfence Server didn´t answer:

    Capture.JPG

     

    I don´t unsterstand the port is rigt the shared secret is right (I use the default testing123):smileysad:

     

    I hope you can help me to get this work.



  • 11.  RE: iap-93 rfc-3576

    Posted Jan 29, 2013 10:32 AM

    @Leon123 wrote:

    Ok I tried it so mutch but it didn´t work.

     

    I configure it like in this link:
    http://www.packetfence.org/bugs//bug_view_advanced_page.php?bug_id=1618

     

    but it won´t work.

     

    The Packetfence Server didn´t answer:

    Capture.JPG

     

    I don´t unsterstand the port is rigt the shared secret is right (I use the default testing123):smileysad:

     

    I hope you can help me to get this work.

    Seems you find my Pull Request in the packetfence Project :smileyvery-happy:
    can you check that your packetfence is listening on 1812 and 1813.
    Besides how is your packetfence instance configuration ? 
    Inline ? outband ?
    Regards,
    Xinity

     



  • 12.  RE: iap-93 rfc-3576

    Posted Jan 29, 2013 10:27 AM

    Packetfence Side:

    - add an Aruba swtich Configuration

    ==> don't forget the Radius Secret

    If you are using the Virtual Controller as a Radius Proxy, use it's IP instead of the IAP Address in the packetfence configuration

     

    Aruba Side:

    in the PEF configuration:

    - add an authentification server:

     - type: Radius

    ==> it seems CoA has been implemented in the latest firmware (juste discovered :)) but i haven't tested it, so i would not tick the CoA Only box.

    - name: [add a fency name]

    - ip: [your packetfence IP]

    - Shared key: [add your Radius Secret Key]

    - RFC3576: Enabled

    - NAS IP: (optional) [your VC IP]

    - NAS identifier: (optional) [a fency name]

     

    This is just the configuration, it really depend on how you use packetfence (inline ou outband) your Vlan Configuration and many more configuration tips.

     

    If you are using Packetfence ZEN, then you should configuration your Wireless network like this:

     

    Aruba Network configuration:

    Vlan:

    - Client Ip Assignement: Network Assigned

    - Client vlan Assignment: Dynamic

    VLAN Assignment Rules: 

    - Attribute: Tunnel-Private-Group-Id contains 1 VLAN: 1

    - Attribute: Tunnel-Private-Group-Id contains 1 VLAN: 4

     

    Security:

    MAC Authentification : enabled

    Authentification server: [your authentification server name]

     

    hoping this helps,

     

    Regards,

     

    Xinity