Security

last person joined: 17 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Does anyone else have issues using VPN on your Guest network?

This thread has been viewed 1 times
  • 1.  Does anyone else have issues using VPN on your Guest network?

    Posted Apr 23, 2014 12:41 PM

    I assumed this was a problem with the user machine until more people started reporting the issue.  The users are able to user their VPN Client successfully for a quite a while but sometimes the connection drops and they have to re-connect with the client.  Their 4G Hotspots work fine with the VPN client as well as other wireless networks.  Any ideas?



  • 2.  RE: Does anyone else have issues using VPN on your Guest network?

    EMPLOYEE
    Posted Apr 23, 2014 01:08 PM

    What is the client VPN?  What is doing the natting for your guest network?



  • 3.  RE: Does anyone else have issues using VPN on your Guest network?

    Posted Apr 23, 2014 01:13 PM

    I would assume a Cisco VPN client.  I believe the Aruba Controller is doing NAT.



  • 4.  RE: Does anyone else have issues using VPN on your Guest network?

    EMPLOYEE
    Posted Apr 23, 2014 01:15 PM
    We need to be sure on both points as well as the VPN configuration (what port the VPN is operating on) otherwise we probably cannot help.


  • 5.  RE: Does anyone else have issues using VPN on your Guest network?

    Posted Apr 23, 2014 01:18 PM

    I will find out, thanks.



  • 6.  RE: Does anyone else have issues using VPN on your Guest network?

    Posted Apr 23, 2014 01:35 PM

    Hello Logan

    The default config of the Captive portal will just let 443 and 80 port so if your client vpn uses another ports it will not work

    If you got Next generation firewall license then you can add other ports to those rules.

     

     

    Cheers

    Carlos



  • 7.  RE: Does anyone else have issues using VPN on your Guest network?

    Posted Apr 23, 2014 02:28 PM

    I would think if this is a firewall issue, users wouldn't be able to connect at all.  That is not the case here.  Users can connect just fine, but the connection drops at random times and they have to re-establish their VPN connectivity.



  • 8.  RE: Does anyone else have issues using VPN on your Guest network?

    Posted Apr 24, 2014 01:56 AM
    I have had issues in the past with VPN products not going through an Aruba necessarily, but going through a NAT. I don't mean to point out the obvious but 'traditional ipsec' does not use TCP or UDP hence it can have issues with nat. I know some devices do sometimes use the spi index to overcome this lack of epheremal source ports on ipsec packets.

    I guess you have checked the log on the controllers for packet drops right?

    Most decent clients nowadays use nat-t (UDP 4500)

    Check the data path session table too?

    Anyone know if there is a nat timeout value?