Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

External DHCP server is not able to assign IP when using 802.11 WPA2 AES

This thread has been viewed 0 times
  • 1.  External DHCP server is not able to assign IP when using 802.11 WPA2 AES

    Posted Sep 10, 2013 08:36 PM

    Hi
    New to Aruba here. I am having an issue where an external DHCP server is not able to assign IP when using 802.11 WPA2 AES. If I test using Open Authentication the DHCP does assign an IP so it does work. Radius server authenticates too.
    Looking at the Controller logs only has "Received DHCP packet from Datpath..."
    Not sure where to proceed from here, any clues would be appreciated.
    Thanks DL77



  • 2.  RE: External DHCP server is not able to assign IP when using 802.11 WPA2 AES

    Posted Sep 10, 2013 09:16 PM

    The encryption type should have no bearing on whether DHCP would work; but the role and/or VLAN assignment may.

     

    Are both using the same role and both using the same VLAN?   For the open network, it would be "Initial Role"; for the 802.1X network it will be the "802.1X Authentiction Default Role"

     

     



  • 3.  RE: External DHCP server is not able to assign IP when using 802.11 WPA2 AES

    Posted Sep 10, 2013 09:38 PM

    Thanks for responding.

     

    The roles are different.  For Open it is Guest, for 802.1X it is Employee I set up previously.  I changed it to Guest and it does work.  I did follow the guide for setup so I am not sure why DHCP doesn't work



  • 4.  RE: External DHCP server is not able to assign IP when using 802.11 WPA2 AES

    Posted Sep 10, 2013 09:42 PM

    run show rights employee and share the results.  



  • 5.  RE: External DHCP server is not able to assign IP when using 802.11 WPA2 AES

    Posted Sep 10, 2013 09:45 PM
      |   view attached

    I have attached to make it easier to read.



  • 6.  RE: External DHCP server is not able to assign IP when using 802.11 WPA2 AES

    Posted Sep 10, 2013 09:48 PM

    DHCP will not be allowed in that setup.  You need a line that reads:

     

    any any svc-dhcp permit

     

    The reason is b/c the client does not have an IP at the time of connection, so the source needs to be "any" not, "172.17.0.0 255.255.255.0"



  • 7.  RE: External DHCP server is not able to assign IP when using 802.11 WPA2 AES

    Posted Sep 10, 2013 10:50 PM

    Perfect thanks for pointing that out.  I will look into the rules further.

     

    Cheers