Security

Reply
Contributor II

HealthCheck CoA and Mac OS X

Hi guys,

 

does someone of you got any expirience with CoA and Mac OS X. 

Today I was at a customer and we configured Onguard. We implemented it wireless and wired so healthchecks can be performed on any client. The customer is using HPE Switches and an Extreme wireless controller.

As dicribed, everythink works fine for WIndows (10) clients. We did the same testing with Mac CLients (wired / wireless) but ended up with same fault.

Client stauts changed and is reported to Clearpass. Clearpass is triggering an CoA and the client is authenticating again (differnt VLAN for healthy / unhelathy clients)

On the wireless controller / switch we can see that the client is in the right VLAN but he starved because of holding a wrong IP address. 

 

What I discovered was that every MAC Client (Mac OS X 10.12.5) we tested act the same. THe clients performs the authentication and after that no DHCP is done. 

 

Again: Does anyone have MAC with ongaurd and CoA up and running? Is there any special setting in MAC OS to change this behaviour?

 

Thanks in advance

 

Guru Elite

Re: HealthCheck CoA and Mac OS X

The wireless controller needs to do a L2 full disconnect. Which CoA/DM profile are you using?

Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Contributor II

Re: HealthCheck CoA and Mac OS X

Till now I use the Motorola pre installed CoA.
As I wrote, it works fine for every Windows machine.
Wired I use the predefined HPE coa

Re: HealthCheck CoA and Mac OS X

Are you using the persistent agent ?
If you are then try using the Agent Bounce option that way you don't need to rely on the CoA
Thank you

Victor Fabian
Lead Mobility Engineer @ Integration Partners
AMFX | ACMX | ACDX | ACCX | CWAP | CWDP | CWNA
Contributor II

Re: HealthCheck CoA and Mac OS X

Thanks for the hint. I was playing with this option but i didn't have that in my mind Right now.
I will try this tomorrow at the customer and will come back to you.

Thanks alot
Contributor II

Re: HealthCheck CoA and Mac OS X

Hi Victor,

 

we tested your solution and it works fine. 

 

Thanks alot again!

Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: