Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass guest will not disable when lifetime over

This thread has been viewed 5 times
  • 1.  ClearPass guest will not disable when lifetime over

    Posted Feb 04, 2016 03:08 AM

    Hi Guys,

    I have deployment Aruba controller , Clearpass for guest. But i find that when guest liftime was gone. Guest still can connect internet. Clearpass using RFC 3576 Server to auth for guest. 

     

    Now, I suspect :

    1.In Clearpass Active Sessions error message: There are no sessions to display. You should enable Insight on at least one node in Policy Manager. (I try to follow tips to enable it but not work)

    2.RFC 3576 Server config issue. 

     

    Any one can give me some advise ? 

     

    Thanks a lot !!

     

     



  • 2.  RE: ClearPass guest will not disable when lifetime over

    Posted Feb 04, 2016 04:08 AM
    Do you have enable the following :
    - Interim Accounting (ClearPass and the controller )
    - CoA (ClearPass and controller shared key matches)


  • 3.  RE: ClearPass guest will not disable when lifetime over

    Posted Feb 04, 2016 04:44 AM

     

    - Interim Accounting (ClearPass and the controller )
    - CoA (ClearPass and controller shared key matches)

    Already have enable.

     

    For example I generate a new guest account, exprie time at after 30 mins, And the lifetime was 10 mins, I login now, after 10 mins i staill in connect, But after 30 mins, I will logout automatic. 

     

    The Clearpass send out the disconnect message should be as same. Why lifetime will invalid ?

    .



  • 4.  RE: ClearPass guest will not disable when lifetime over

    EMPLOYEE
    Posted Feb 05, 2016 05:17 AM

    Hi Gary,

     

    Please let me know the ClearPass version. 

     

    Do you have the following enforcement profiles mapped/applied in the guest user authentication service in policy manager?

     

    xxx Guest Do Expire

    xxx Guest Expire Post Login

     

    The "expire post login enfircement profile" is the one which will mark the guest expiry based on account lifetime after the guest user first login. These profiles will be created automatically when you create the gueste authentication service using the service templates.

     

    Guest Expire Post Login(Template:ClearPass Entity Update Enforcement).

     TypeName Value
    1.Expire-Time-UpdateGuestUser=%{GuestUser:expire_postlogin}

    Guest Do Expire(Template:Session Restirction Enforcement). 

     TypeName Value
    1.Expiry-CheckExpiry-Action=%{GuestUser:do_expire}


  • 5.  RE: ClearPass guest will not disable when lifetime over

    Posted Feb 15, 2016 01:52 AM

    Hi Saravanan,

    Thank of you reply, The issue was fixed. 

    In the system setting, I forgot enable the insight function.