Security

Reply
Regular Contributor II

How to force auto join to the eap-tls ssid after onboarding

Hi forum,

 

My onboarded devices are not automatically joining the EAP-TLS ssid. I have an open ssid that will get you to the provisioning page and after you're done you should automatically connect to the secure EAP-TLS ssid. I have my network configured like this:

Screen Shot 2015-08-04 at 11.49.39 AM.png

 

But still no luck. I have to click on the EAP-TLS ssid after I onboard in order to join it. any idea? 

Aruba Employee

Re: How to force auto join to the eap-tls ssid after onboarding

What version of ClearPass are you running?

 

Also, does change status from Access Tracker work?

Thanks,

Zach Jennings
Regular Contributor II

Re: How to force auto join to the eap-tls ssid after onboarding

clearpass is 6.5

and change status isn't working. I'm looking to automate the disconnect from the open ssid and the reconnect to the eap-tls ssid.

Re: How to force auto join to the eap-tls ssid after onboarding

You should check to see that RFC3576 (CoA) is enabled and working.  Check the controller and also the Network Device in ClearPass.

Seth R. Fiermonti
Consulting Systems Engineer - ACCX, ACDX, ACMX
Email: seth@hpe.com
-----
If you found my post helpful, please give kudos
Regular Contributor II

Re: How to force auto join to the eap-tls ssid after onboarding

thanks Seth, how do I test CoA working or not? I know on my aaa profile I have ccpm there with the same psk.

Guru Elite

Re: How to force auto join to the eap-tls ssid after onboarding

In access tracker, click the most recent request for a currently connected client and click the Change Status button at the bottom and then choose [Aruba Terminate Session].



Sent from Mail for Windows 10

Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Aruba

Re: How to force auto join to the eap-tls ssid after onboarding

Mac devices will not switch ssid. They like to hold onto the original one. You will need to make sure you are on boarding in the same ssid and then send a coa disconnect
Thank You,
Troy

--Give Kudos: found something helpful, important, or cool? Click Kudos Star in a post.

--Problem Solved? Click "Accepted Solution" in a post.
Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: