Security

last person joined: 23 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM Mac Caching does not work correctly

This thread has been viewed 9 times
  • 1.  CPPM Mac Caching does not work correctly

    Posted Feb 06, 2015 04:13 AM

    Hello,

     

    Mac Caching with CPPM does not work correctly.

    OUr guest users are redirected to a captive portal when they connect for the first time. Generally Clearpass checks if the device is already in de endpoint database, because users should only are forced to login via captive portal once a day.

     

    But in Access Tracker of CPPM I can see that this is not working.

    I logged in with a new ipad on my captive portal. Everything is ok. Mac Caching fails as expected.

    I disconnected the ipad via the aruba management gui and tried to reconnect.

    Then i was prompted to login via captive portal again.

    Access tracker shows that mac caching failed. I checked endpoint database and i found the ipad correctly.

    Accesstracker shows following Error

     

    cppm error.jpg

     

    Does anybody has an idea about this problem?

     

    Thanks a lot



  • 2.  RE: CPPM Mac Caching does not work correctly

    EMPLOYEE
    Posted Feb 06, 2015 04:38 AM
    Did you creat the two services with the guest Mac auth template? Is insight enabled? You need to post a screen shot of summary.if you answered either one no then you might need to post screen shots of the services and each tab


  • 3.  RE: CPPM Mac Caching does not work correctly

    Posted Feb 06, 2015 07:14 AM


  • 4.  RE: CPPM Mac Caching does not work correctly

    Posted Feb 06, 2015 07:14 AM


  • 5.  RE: CPPM Mac Caching does not work correctly

    Posted Feb 09, 2015 05:36 AM

    Does anyone have an idea?



  • 6.  RE: CPPM Mac Caching does not work correctly

    Posted Feb 09, 2015 06:23 AM

    you didn't answer:

    • Did you create the two services with the guest Mac auth template?
    • Is insight enabled?
    • You need to post a screen shot of summary.


  • 7.  RE: CPPM Mac Caching does not work correctly

    Posted Feb 09, 2015 08:49 AM

    The Services were not created with the template.

    Insight is enabled yes.

    Screenshots you can find in my postings above



  • 8.  RE: CPPM Mac Caching does not work correctly

    Posted Feb 15, 2015 07:02 AM

    not the screenshot of the summary of the access tracker.

     

    also are these clients in your endpoint repository?



  • 9.  RE: CPPM Mac Caching does not work correctly

    Posted Feb 15, 2015 08:52 AM

    from your screenshot, your endpoint is in unknown state.

    add another enforcement policy in your CP service to do post-authentication action to change the state to known after a succesful CP login.

     

    Ricky.



  • 10.  RE: CPPM Mac Caching does not work correctly

    Posted Feb 23, 2015 03:17 AM

    @rickylee wrote:

    from your screenshot, your endpoint is in unknown state.

    add another enforcement policy in your CP service to do post-authentication action to change the state to known after a succesful CP login.

     

    Ricky.


    How can I do this? In Post Enforcement Profile "Guest Mac Caching" i can't find an attribute to change status.


  • 11.  RE: CPPM Mac Caching does not work correctly

    Posted Mar 06, 2015 12:59 AM

    Can anyobody help?



  • 12.  RE: CPPM Mac Caching does not work correctly

    Posted Mar 06, 2015 06:08 AM

    for testing purposes, you can change the endpoint state from unknown to known manually from endpoint database.

    have you tried tim's suggestion to change auth method to all mac auth?

    can you show the services screen where the auth fails?

     

    Ricky



  • 13.  RE: CPPM Mac Caching does not work correctly
    Best Answer

    EMPLOYEE
    Posted Mar 06, 2015 03:15 PM

    If you use the service template for MAC caching, it will create all the necessary enforcement actions.



  • 14.  RE: CPPM Mac Caching does not work correctly

    Posted Mar 23, 2015 04:58 AM

    I now created the Service via template. OK Mac caching is working. But now I have another question.

    There seems to be a limit now for the total amount of guet accounts correlated connected  devices.

    I'm sure it is not the value of "simultaneuos_use" of guest module. Where can i modify this limit? And where can i lookup how many connected machines one user uses?



  • 15.  RE: CPPM Mac Caching does not work correctly

    EMPLOYEE
    Posted Feb 15, 2015 11:07 AM
    Use AllowAll MAC-auth as the authentication method instead of just MAC-auth. 


    Thanks, 
    Tim