Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Captive Portal Redirects to login after sucessful auth

This thread has been viewed 6 times
  • 1.  Captive Portal Redirects to login after sucessful auth

    Posted Sep 02, 2014 11:28 AM

    Hi Guys,

     

    Quick question, I hope.

     

    I'm using a 7210 controller and 2 x CPPM devices.

     

    Dell OS Version 6.3.1.10

    Dell CPPM Version 6.3.4.65370

     

    I've configured a guest SSID with a CPPM guest captive portal. The captive portal URL points to the DNS name which resolves to the Virtual IP address.

     

    I've setup self registration but it's redirecting back to the captive portal login page after sucessful authentication.


    I'm also using the CPPM Virtual IP as my RADIUS server for this SSID on the controller.

     

    When I swap the portal URL to CPPM1 server and use CPPM1 as the RADIUS it works.

     

    I need to do some more investigation before I say what I think is happening.

     

    Can anyone tell me why this is happeninig?

     

    Cheers

    J


    #7210


  • 2.  RE: Captive Portal Redirects to login after sucessful auth

    Posted Sep 02, 2014 01:07 PM
    Do you have the VIP as your AAA radius server in your controller ?


  • 3.  RE: Captive Portal Redirects to login after sucessful auth

    Posted Sep 02, 2014 01:18 PM
    Hi Victor,

    Yes I do.


  • 4.  RE: Captive Portal Redirects to login after sucessful auth

    EMPLOYEE
    Posted Sep 02, 2014 01:20 PM

    Is COA enabled for the VIP as a RFC3576 in your controller



  • 5.  RE: Captive Portal Redirects to login after sucessful auth

    Posted Sep 03, 2014 04:20 AM

    Well, if you're doing normal guest captive portal with Controller Initiated login then CoA doesn't come into account during this first login.

     

    Since you have CPPM VIP I'm assuming this this a CPPM cluster setup using Publisher - Subscriber as Standby Publisher. Can you verify that the cluster is in sync and that your cppm1 is designated Publisher?

     

    Any related entries in the Access Tracker and Event viewer you can share?

     

     

    Other thoughts..

    What you describe tho is a common scenario when Radius doesn't go through, is rejected due to missing/wrong Radius config (secret, wrong controller IP used as device etc), the correct service doesn't hit. 

    -> Is there perhaps some firewall/access list denying Radius from Controller to the VIP?

     

    Anything in the logs on the controller?

     

     



  • 6.  RE: Captive Portal Redirects to login after sucessful auth

    Posted Sep 03, 2014 04:55 AM

    The VIP appears to be associated with CPPM2 as when I browse to it I can clearly see that it's not the publisher I'm on.

     

    CPPM1 is my designated publisher.

     

    However when I look at the VIP settings it's telling me that the VIP is associated with CPPM1.

     

    Here you can see the publisher is set to 002 which is CPPM1 with a .162 address

    2014-09-03 09_48_16-ClearPass Policy Manager.png

     

    Here you can see the VIP is associated with 002 (CPPM1) 

    2014-09-03 09_49_49-ClearPass Policy Manager.png

     

    When I browse tot he VPN you can see I'm not on the publisher!

    2014-09-03 09_53_29-ClearPass Policy Manager.png

     

    Thoughts?



  • 7.  RE: Captive Portal Redirects to login after sucessful auth

    Posted Sep 03, 2014 05:47 AM

    Well - not anything good ;)

     

    Check the VIP settings when logged on to the CPPM2. Verify that VIP settings show the same as on CPPM1.

    Is this a production system or can you try some things like stopping/starting VIP service on both CPPM's, deleting VIP and re-establishing it.. Try pinging the VIP address at intervals when you do this to see if it stops responding when it should ;)

     

     



  • 8.  RE: Captive Portal Redirects to login after sucessful auth

    Posted Sep 03, 2014 06:24 AM

    I rebooted CPPM2 whilst pinging the VIP. The VIP stopped responding to pings till CPPM2 came back online.

     

    service restart all on CPPM1 seems to have "woken" it back up.

     

    The VIP appears to be working ok now.

     

    Thanks Guys.



  • 9.  RE: Captive Portal Redirects to login after sucessful auth

    Posted Sep 03, 2014 06:53 AM

    Great news!

    If you don't mind me asking - is this a new installation so that there hasn't been any reboots after VIP and Cluster was established?

     

    Just adding to my own "experience database" for future reference :)

     



  • 10.  RE: Captive Portal Redirects to login after sucessful auth

    Posted Sep 03, 2014 07:24 AM

    Actually it's still broken. Always seems to point at CPPM2 even though CPPM1 is up.

     

    Also I just rebooted CPPM2 and checked the VIP which stopped responding to pings and it showed as not being assigned. 

     

    Will call TAC. Dell TAC though. :(



  • 11.  RE: Captive Portal Redirects to login after sucessful auth

    EMPLOYEE
    Posted Sep 03, 2014 07:27 AM

    Are these virtual or hardware appliances?

     

    If virtual, are your vSwitches configured to Accept Forged Transmits?

     

    vmware-forged-tx.JPG



  • 12.  RE: Captive Portal Redirects to login after sucessful auth

    Posted Sep 03, 2014 07:44 AM

    They're physical appliances.



  • 13.  RE: Captive Portal Redirects to login after sucessful auth

    Posted Sep 10, 2014 08:21 AM

    Both ClearPass instances think they're the active virtual IP host.

     

    2014-09-03 09_49_49-ClearPass Policy Manager.png

     

    We've removed and re-added the virtual IP setting to no avail. Dell and Aruba TAC are investigating.



  • 14.  RE: Captive Portal Redirects to login after sucessful auth

    Posted Sep 10, 2014 10:37 AM

    Removed Virtual IP settings

    Removed standby publisher settings

    Dropped subscriber

    Ran make subscriber

    Added virtual IP settings

    Checked and both nodes still show as the current node of virtual IP.

     

    Anyone else running virtual IP settings??



  • 15.  RE: Captive Portal Redirects to login after sucessful auth

    EMPLOYEE
    Posted Sep 10, 2014 10:40 AM
    The only time I have seen that issue is where there is a firewall between and the heartbeat is being blocked between the cluster from the subscriber.


  • 16.  RE: Captive Portal Redirects to login after sucessful auth

    Posted Sep 10, 2014 10:42 AM
    Installed the same setup you have at a customer site with VIP - no problems.
    You sure there is wide open Layer2 connection between those two boxes? Just asking since problems in that area could give those symptoms.


  • 17.  RE: Captive Portal Redirects to login after sucessful auth

    Posted Sep 10, 2014 10:54 AM

    Customer assures me there's no firewall between the clearpass instances. They're both on the same VLAN within the same building. 



  • 18.  RE: Captive Portal Redirects to login after sucessful auth
    Best Answer

    Posted Sep 26, 2014 05:53 AM

    UPDATE!

     

    To rule out the wired infrastructure we patched both ClearPass instances into the same switch. We still saw the same behaviour though.


    Tried patching both ClearPass into another switch and boom! Well not boom, but VRRP started working as expected.

     

    Looked like an issue with the Dell switch the customer was using.

     

    Switch model Dell N2048P 
    Firmware 6.0.1.3
     
    We patched 1 ClearPass back into the Dell switch and VRRP immediately stopped working normally. E.g. both ClearPass instances believed they were the primary for the virtual IP.
     
    We showed Dell who replicated it in their lab. 
     
    After some time Dell provided a workaround which is to disable IGMP Snooping on their switch.
     

    console (config)# no ip igmp snooping

    console (config)# end

     

    Cheers

    James



  • 19.  RE: Captive Portal Redirects to login after sucessful auth

    Posted Sep 26, 2014 05:57 AM

    Well done! Thanks for providing the solution to this problem.



  • 20.  RE: Captive Portal Redirects to login after sucessful auth

    Posted Oct 23, 2014 06:24 AM

    Additional information...

     

    Clearpass is using UCARP not VRRP to share a common virtual IP address between instances.

     

    Currently Dell switches (see details below) do not support the UCARP protocol. 

    As mentioned disabling IGMP snooping is a workaround to get this working.

     

    UCARP has been put forward as a feature request.

     

    Switch details:

    Dell Networking N2048P

    OS 6.0.1.3

     

    May not be limited to this model and OS.


    Cheers
    James