Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CoA after MACtrac device registering

This thread has been viewed 11 times
  • 1.  CoA after MACtrac device registering

    Posted Jul 21, 2017 05:04 AM

    Hi,

     

    With MAC auto fill on the MACtrac device page, it is possible for a user to register it´s device without knowing the MAC address.

     

    If the user has registered the device, is it possible to send a CoA for that MAC so that the device will go into the role for registered devices?

     

    Thanks,

    Christian



  • 2.  RE: CoA after MACtrac device registering

    EMPLOYEE
    Posted Jul 21, 2017 07:40 AM
    Device Registration is commonly used for headless devices. Is that not the case in your environment?


  • 3.  RE: CoA after MACtrac device registering

    Posted Jul 21, 2017 07:58 AM

    Maybe my wording was wrong.

    What is the name for device self registration by a user?

     

    Our workflow is that the user connects to the Guest SSID with the device that should get registered.

    On the Guest captive Portal page is a link to the Device registration page.

    The user needs to login with AD credentials and can then register the device. The MAC of the device is already filled.

     

    When the user has entered the name of the device and clicked on Submit, the device is registered but the user is still in the to-be-registered role. A CoA could drop the device and make it authenticate with MAC auth next time.

     

    As we couldn´t find a way to make this work, we tell the users to connect to another SSID which only does MAC auth for registered devices.

    This is what I would like to remove.



  • 4.  RE: CoA after MACtrac device registering

    EMPLOYEE
    Posted Jul 21, 2017 08:03 AM
    So these are standard user devices with a browser (Win, Android, Mac, iOS) or headless/IoT devices like Chromecasts, printers, Apple TVs, game console, etc?

    Device registration can be used for both but it's really designed for the latter.

    Aftet a device registered, so you see a WEBAUTH request in ClearPass?


  • 5.  RE: CoA after MACtrac device registering

    Posted Jul 21, 2017 08:09 AM

    Standard devices.

     

    You are right. there is a WEBAUTH entry that seems to do the CoA.

     

    Is this the way it works?

     

    Then we need to check why the CoA isn´t working.



  • 6.  RE: CoA after MACtrac device registering

    EMPLOYEE
    Posted Jul 21, 2017 08:13 AM
    You need to create a WEBAUTH service to handle those requests with a Disconnect or CoA profile.

    I posted an example here yesterday: http://community.arubanetworks.com/t5/Security/CoA-on-EndPoint-Change/m-p/302483#M32727

    Just out of my own curiosity, why are you using device registration for regular devices instead of 802.1X?


  • 7.  RE: CoA after MACtrac device registering

    Posted Jul 21, 2017 10:06 AM

    We have that WEBAUTH and it triggers after a device registration.

    But it seems there is no CoA sent to the controller.

    How does CPPM know to which controller it needs to send the CoA?

    The "Access Device IP/Port:" Field is empty in Access Tracker.

     

    This is a BYOD use case.

     

    We looked into CPPM onboard but decided for MACtrac.

    802.1x wasn´t looked at right now. We might do so later.

     

    Thanks,

    Christian

     

     



  • 8.  RE: CoA after MACtrac device registering

    EMPLOYEE
    Posted Jul 21, 2017 10:13 AM

    Do you have RADIUS accounting enabled?

    In access tracker on the webauth request, is there a CoA tab?



  • 9.  RE: CoA after MACtrac device registering

    Posted Jul 21, 2017 06:10 PM

    Enabling Radius accounting and configuring rfc-3576 did the trick.

    The WEBAUTH does now sends a CoA and the device authentictes next time with the Guest MAC service.

     

    Last thing that is missing is to return the sponsor name as username to

    the controller to replace the MAC in "show user".

    Returning

    Radius:IETF

    User-Name=%{Endpoint:Username}

    doesn´t work as the Endoint doesn´t have any attributes.

    Standard Guest devices have all kinds of attributes.

    The sponsor name would be the user who has registered the device via MACtrac.

     

    How can we add the attributes to the device?

     

    Thanks,

    Christian



  • 10.  RE: CoA after MACtrac device registering

    EMPLOYEE
    Posted Jul 21, 2017 06:15 PM
    %{Authorization:[Guest Device Repository]:SponsorName}


  • 11.  RE: CoA after MACtrac device registering

    Posted Jul 21, 2017 09:10 PM

    That works. Thanks!

     

    During my testing, I noticed that some times the CoA isn´t sent.

    When this happens there is no Radius Response entry under the Output tab in Access Tracker for the WEBAUTH event.

    If the CoA is sent, there is the Radius:IETF:Calling-Station-Id attribute with the client mac in Access Tracker.

     

    I have attached the logs when it doesn´t work and when it works.

     

    Time for a TAC case?

     

    Thanks,

    Christian

     

     

    Attachment(s)

    txt
    Request_Logs-no-coa.txt   14 KB 1 version
    txt
    Request_Logs-coa.txt   15 KB 1 version


  • 12.  RE: CoA after MACtrac device registering

    EMPLOYEE
    Posted Jul 21, 2017 09:20 PM

    The best place to look is the device's last RADIUS authentication in Access Tracker. Is there a CoA tab after Output?

     

    From the logs you attached, it looks like there is no active session for that MAC address so the disconnect message isn't crafted/sent.



  • 13.  RE: CoA after MACtrac device registering

    Posted Jul 21, 2017 09:28 PM

    When the radius mac auth succeeds there is a CoA tab.

     

    Could it be that the RADIUS Accounting message takes some time to be sent to CPPM? And without, there is no session in CPPM and no CoA sent?

     



  • 14.  RE: CoA after MACtrac device registering

    EMPLOYEE
    Posted Jul 21, 2017 09:43 PM
    Potentially, but I've never seen that happen. Guess it's best to open a TAC case.


  • 15.  RE: CoA after MACtrac device registering
    Best Answer

    Posted Aug 04, 2017 10:10 AM

    That is solved.

     

    We are using MACtrac in combination with guest mac caching.

    The initial MAC auth of the device that should be registered, need to be accepted by clearpass. By default it is rejected.

    When it is accepted and a captive portal role is pushed, the CoA follogin the reistering of the device works then reliable.



  • 16.  RE: CoA after MACtrac device registering

    MVP
    Posted Aug 09, 2018 02:21 PM

    @cappalli wrote:
    So these are standard user devices with a browser (Win, Android, Mac, iOS) or headless/IoT devices like Chromecasts, printers, Apple TVs, game console, etc?

    Device registration can be used for both but it's really designed for the latter.

    Aftet a device registered, so you see a WEBAUTH request in ClearPass?

    Should you also see a WEBAUTH when creating a Guest Account through the api with CoA set as true? I am not seeing the WEBAUTH on CPPM 6.6.x.



  • 17.  RE: CoA after MACtrac device registering

    EMPLOYEE
    Posted Aug 09, 2018 02:23 PM
    Device registration, yes. Guest account, no.


  • 18.  RE: CoA after MACtrac device registering

    MVP
    Posted Aug 09, 2018 02:29 PM

    @cappalli wrote:
    Device registration, yes. Guest account, no.

    That is the purpose of the CoA flag when creating a guest account using POST then? API Explorer says:

     

    2018-08-09_1425.png



  • 19.  RE: CoA after MACtrac device registering

    EMPLOYEE
    Posted Aug 09, 2018 02:31 PM
    Just an oversight. I’ll get it removed.

    Dynamic Authorization would provide no value when creating a guest account.


  • 20.  RE: CoA after MACtrac device registering

    MVP
    Posted Aug 09, 2018 02:33 PM

    If a user is self-registering, the CoA could serve to log them in much like tle login button already in the CPPM Guest self-registration process.



  • 21.  RE: CoA after MACtrac device registering

    EMPLOYEE
    Posted Aug 09, 2018 02:36 PM
    That would be handled by the out of box NAS configuration.