Higher Education

Reply
This is an open group. Sign in and click the "Join Group" button to become a group member and start posting.

Re: Can I use DHCP Snooping to poplate missing Framed-IP-Attribute in the Radius Accounting Proxy??

Many thanks Ryan, If I have a cluster do I need to do that on both nodes?

Also did anyone know if it was possible to delay the forwarding on the RADIUS Accounting packets in the RADIUS proxy until the profiler knows the IP address of the endpoint?
MVP

Re: Can I use DHCP Snooping to poplate missing Framed-IP-Attribute in the Radius Accounting Proxy??

Only one endpoint profiler needs to be enabled per zone in a cluster. Obviously if that one goes offline, you won't be profiling so weigh your risk appetite for profiling.

In terms of delaying the sending of radius accounting, policy manager is very flexible, but you'd likely have to get really creative on how to pull that off (assuming it's possible). You could do something likely initially setting the session timer to very short, which would force the endpoint to reauthenticate. The thought would be that at reauthentication, the IP would be learned - but you'd need to be sure to not send the short session timer at that point. And you'd have to reset so that next time around at initial connection, it uses the short timer.

This is really an area where aruba professional services would be worthwhile.
==========
Ryan Holland, ACDX #1 ACMX #1
The Ohio State University
Highlighted

Re: Can I use DHCP Snooping to poplate missing Framed-IP-Attribute in the Radius Accounting Proxy??

I have been working with an Aruba professional. Together we came up with the short session / normal session (which I affectionately call the Meraki Bounce Bodge). The problem with the short session solution is that it breaks the roaming logic of the SSO module on the SonicWall. It is so frustrating to be so close and yet so far.
Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: