Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Client was able to associate although failed authentication

This thread has been viewed 1 times
  • 1.  Client was able to associate although failed authentication

    Posted May 03, 2017 03:37 AM

    Hi all,

     

    I'm setting up a basic SSID with MAC address authentication on the mobility controller, using the endpoint list on CPPM as database for authentication. My test so far has had unexpected result, as the client was still able to associate and got IP address from DHCP, although it failed authentication. Below is my current config/status on mobility controller and CPPM:

     

    Mobility Controller configuration (I use default config on guest and logon role):

    1.PNG

     

    2.PNG

     

    CPPM log:

    CPPM failed authen log

     

    Mobility Controller - client still associated:

    4.PNG

     

    Please let me know if there's anything wrong with my setup. I really appreciate your help.

     

    Thank you,



  • 2.  RE: Client was able to associate although failed authentication

    EMPLOYEE
    Posted May 03, 2017 04:36 AM

    If a client fails mac authentication and you have an initial role configured, failing mac authentication means that they still get the initial role.  In advance configurations, they theoretically can still get an ip address and then "register" to the captive portal to then get access.  A user who is already registered can skip the captive portal in that instance because they would pass mac authentication.  If you want the client to just be rejected, do not configure an initial role.



  • 3.  RE: Client was able to associate although failed authentication

    Posted May 03, 2017 04:45 AM

    Hi Colin, 

     

    Can you tell me how to not attach the initial role to the SSID? It looks like the GUI doesn't have such option.

     

    5.PNG



  • 4.  RE: Client was able to associate although failed authentication

    Posted May 03, 2017 04:55 AM

    Hi Colin,

     

    Can you tell me how to not attach the initial role to SSID? It looks like the GUI doesn't have such option.

     

    5.PNG



  • 5.  RE: Client was able to associate although failed authentication

    Posted May 03, 2017 05:08 AM

    Hi Colin,

     

    Can you tell me how to not attach the initial role to SSID? It looks to me the GUI doesn't have such option.

    5.PNG



  • 6.  RE: Client was able to associate although failed authentication

    Posted May 03, 2017 05:44 AM

    Hi Colin,

     

    Can you tell me how to not attach the initial role to SSID? It looks like the GUI doesn't have such option.

     

    5.PNG



  • 7.  RE: Client was able to associate although failed authentication

    Posted May 03, 2017 10:18 AM

    Hi Colin,

     

    Can you please tell me how to not attach the initial role to SSID? It looks to me the GUI doesn't have such option.

     

    Capture.PNG