Security

Reply
MVP
Posts: 385
Registered: ‎05-09-2013

Clearpass + HP Switch Integration - Not receiving IP address

Hi AirHeads Community,

 

I'm working with a customer who wants to have 802.1X wired authentication on his HP switches. I configured a test switch and port for 802.1X eap-peap authentication and have connected a laptop. In ClearPass I see the request being Accepted and using the default [Allow Access Profile] as the enforcement. Customer has 'untagged vlan 1' on the switch ports and they only use VLAN 1 on this network. After successful authentication, client is not receiving an IP address however. I'm not sure if I need to change the enforcement profile or if it's something on the switch that needs to be updated.

 

wired configuration is as follows:

 

interface I22

 untagged vlan 1

 aaa port-access authenticator

 aaa port-access authenticator quiet-period 5

 aaa port-access authenticator reauth-period 30

 aaa port-access authenticator auth-vid 1

 aaa port-access authenticator unauth-period 10

 aaa port-access authenticator logoff-period 862400

 aaa port-access authenticator client-limit 1

aaa port-access controlled-direction in

 

 

any ideas? Thanks!


Michael Haring | Senior Network Engineer
Comm Solutions, an Optiv Security Company
www.commsolutions.com | www.optiv.com
MVP
Posts: 4,301
Registered: ‎07-20-2011

Re: Clearpass + HP Switch Integration - Not receiving IP address

Do you have a DHCP relay configured for that VLAN pointing to DHCP server either on the switch uplink or the actual switch ?

Sent from Outlook Mobile
Thank you

Victor Fabian
Lead Mobility Engineer @ Integration Partners
AMFX | ACMX | ACDX | ACCX | CWAP | CWDP | CWNA
Guru Elite
Posts: 8,647
Registered: ‎09-08-2010

Re: Clearpass + HP Switch Integration - Not receiving IP address

If you remove the port ACL, does it work?

Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
MVP
Posts: 385
Registered: ‎05-09-2013

Re: Clearpass + HP Switch Integration - Not receiving IP address

According to the customer, the switch ports with no authentication are receiving DHCP. However, the VLAN 1 on the switch is configured as 172.18.151.241/24. the VLAN that the users are receiving is also VLAN 1, but they are getting addresses in the 172.18.200.0/24 subnet apparently. I don't know how this is possible. I might have to have them move the connection to verify.


Michael Haring | Senior Network Engineer
Comm Solutions, an Optiv Security Company
www.commsolutions.com | www.optiv.com
MVP
Posts: 385
Registered: ‎05-09-2013

Re: Clearpass + HP Switch Integration - Not receiving IP address

Just verified, even with the existing network configuration, by removing the authentication from the port, DHCP works correctly.


Michael Haring | Senior Network Engineer
Comm Solutions, an Optiv Security Company
www.commsolutions.com | www.optiv.com
MVP
Posts: 385
Registered: ‎05-09-2013

Re: Clearpass + HP Switch Integration - Not receiving IP address

Although I still don't understand exactly how they manage to receive IPs, apparently their DHCP server had no IP addresses left because they use 8 day lease times. We managed to free up some IPs and everything worked.

 

Thanks for the help


Michael Haring | Senior Network Engineer
Comm Solutions, an Optiv Security Company
www.commsolutions.com | www.optiv.com
Search Airheads
Showing results for 
Search instead for 
Did you mean: