Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM 6.0 with management and data interfaces. Networking issues

This thread has been viewed 2 times
  • 1.  CPPM 6.0 with management and data interfaces. Networking issues

    EMPLOYEE
    Posted Feb 07, 2013 02:17 PM

    Hi

     

    I'm trying to set un a CPPM 6.0 with guest connect using one public frontend data interface and one private backend management interface. I've observed that, whenever I turn on the data interface, I start having networking issues with the mgmt interface.

     

    I've modified the routing table via cli (network ip add -d ....) and some issues have gone (I can now validate against my AD). However, my CPPM is still not listening to incoming RADIUS traffic. There seems to be some routing table issue, for as soon as I turn off the data interface everything starts working just fine.

     

    Have any of you guys had a similar problem?

     

    Thanks a lot

     

    Regards

     

    Samuel



  • 2.  RE: CPPM 6.0 with management and data interfaces. Networking issues

    EMPLOYEE
    Posted Feb 07, 2013 02:59 PM

    I think I already know the answer. Is it right, that, once enabled, CPPM uses the data port both for web portal and RADIUS traffic? Do any of you guys know if this behaviour can be altered in any way? I would certainly prefer to have the RADIUS traffic coming through the management port...

     

    BTW. Did Amigopod work in the same way? From what I recall, the RADIUS traffic went through the management port in Amigopod... Am I right? If so, Why the change?

     

    Thanks for the help



  • 3.  RE: CPPM 6.0 with management and data interfaces. Networking issues

    Posted Feb 09, 2013 09:53 AM

    would be interested in some official Aruba statement on this also, from previous deployments i just use one interface, trying with two just doesn't work out as expected.



  • 4.  RE: CPPM 6.0 with management and data interfaces. Networking issues

    EMPLOYEE
    Posted Feb 11, 2013 02:38 PM

    Hi

     

    I didn't come up to that conclusion by myself. I opened a TAC case and they told me that, once you enable the data port, the management port stops working for anything else than management.

     

    I've managed to use it for database (AD) queries by adding static ip routes from the CLI interface. Sadly, that didn't with RADIUS traffic.

     

    Regards