Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Cearpass to Fortigate RSSO issue

This thread has been viewed 22 times
  • 1.  Cearpass to Fortigate RSSO issue

    Posted May 12, 2016 04:52 AM

    Good day,

     

    We are experiencing intermittent issues with our RSSO service set up between Clearpass and Fortigate firewalls. We get about 20 (of about 300) users a day that does not get RSSO, usually after lunch when the users went out and came back into the building.

     

    We have found that usually these users have a short connectivity time on the mobility controllers but have not authenticated to Clearpass for RADIUS authentication (No corresponding entry in the Access Tracker). If we delete the user from the controller using the "aaa user delete mac ... " command we get an entry in the access tracker and the user gets RSSO on the Firewall.

     

    We have disabled OKC for the SSID, and also send the accounting information directly from the controller as well, but none of these changed the situation.

     

    Any suggestions?



  • 2.  RE: Cearpass to Fortigate RSSO issue

    Posted May 23, 2016 11:30 AM

    What's the value of your "Logon User Lifetime" found under Authentication -> Advanced??



  • 3.  RE: Cearpass to Fortigate RSSO issue

    Posted May 23, 2016 11:57 AM

    David,

     

    Thank you for the reply.

     

    Logon User Lifetime is set to 5 minutes (default value)

     

    Kind Regards,

    Albie



  • 4.  RE: Cearpass to Fortigate RSSO issue

    Posted May 23, 2016 12:05 PM

    How about the "User idle timeout" setting under the AAA profile for your particular service.

    If it is not already, you could try enabling this and setting the value to 0 so that entries are deleted upon disassociation or disconnect.



  • 5.  RE: Cearpass to Fortigate RSSO issue

    Posted Jul 19, 2022 09:12 AM
    It's behavior that is fixed configuring: Server configuration > "CPPM server name" > Service Parameters > Policy Server > Additional time before session deletion from mult-master cache > set to 600. (default is 0). It works every time for me.