Security

last person joined: 22 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Issue - COA enforcement profile never send to NAS

This thread has been viewed 12 times
  • 1.  Issue - COA enforcement profile never send to NAS

    MVP EXPERT
    Posted Apr 08, 2018 05:21 AM
      |   view attached

    I focus a strange problem when i use  a [ArubaOS Switching - Terminate Session] enforcement profile, the radius response is vissible in accesstracker but never sends by clearpass to de NAS device. The radius response packets are not vissible in Wireshark and never sends to the NAS.

     

    I Solved the problem by making a clone of the [ArubaOS Wireless - Terminate Session] template and change the attributes to be equal to the  [ArubaOS Switching - Terminate Session] template. 

     

    It seems like i bug to me in Clearpass 6.7.2.105008.

    The switch a 2920 with fw16.04 isnt the problem here, the problem is clearpass never sends de radius response that access tracker showns.

     

    One thing i notice is that when i do a manualy COA in a accepted radius request in accesstracker only the wireless COA enforcement profiles are visible here.

     

    Are other people seen the same issue here? Or do i missed something?

    See also attechment with some screenshots of the issue in my test enviornment ;)

     

     

     

     

     

     

    Attachment(s)

    pdf
    COA ISSUE.pdf   627 KB 1 version


  • 2.  RE: Issue - COA enforcement profile never send to NAS
    Best Answer

    EMPLOYEE
    Posted Apr 08, 2018 08:58 AM
    1) A terminate session is a Disconnecf Message not a CoA
    2) is your switch defined as Hewlett-Packard-Enterprise in Network Devices?


  • 3.  RE: Issue - COA enforcement profile never send to NAS

    MVP EXPERT
    Posted Apr 08, 2018 09:34 AM
      |   view attached

    Hi Tim,

     

    Thanks for your explenation. Actually disconnect request use coa port 3799 UDP, so thats why i called it COA. when i look in the show radius dyn-authorization, your right, its a disconnect message.

     

    My Switch is in the vendor name group "aruba", so its a aruba 2920 switch. Actually it seem go like wrong here, if i change it to HPE switches then is looks beter.  :) so there you right to ;)

     

    only dont see a different in de enforcement profiles what hists that choice. 

     

     



  • 4.  RE: Issue - COA enforcement profile never send to NAS

    EMPLOYEE
    Posted Apr 08, 2018 09:35 AM
    Make sure you follow the ClearPass Solution Guide for Wired Policy Enforcement.


  • 5.  RE: Issue - COA enforcement profile never send to NAS

    Posted Jul 09, 2018 06:35 AM

    hi mkk,

     

       im currently using Aruba 2920 WB.16.06.0006 and CPPM 6.7.3.106.273

     

    changed device settings to HPE, still CoA 3799

     

    but  still i get  "Aruba OS Switching - Bounce Switch Port failed for client .." error

     Aruba 135 still on untrust VLAN but was able identified under End-Host identifier

     

    im currently testing Device Profiling with VLAN enforcement

     

    any suggestions? TIA :)

     

     



  • 6.  RE: Issue - COA enforcement profile never send to NAS

    MVP EXPERT
    Posted Jul 09, 2018 05:58 PM
    Be sure you have in you NAD device set the Vendor Name to Hewlett-Packard-Enterprise.

    Second be sure you have dynamic authorization enabled on your switch.
    radius-server host “cppm-ip” dyn-authorization


  • 7.  RE: Issue - COA enforcement profile never send to NAS

    Posted Jul 10, 2018 01:15 AM

    Hi mkk,

     

     thanks for your response. already did that. however error still remains. please see attached images.

     

     

    thank you



  • 8.  RE: Issue - COA enforcement profile never send to NAS

    MVP EXPERT
    Posted Jul 10, 2018 04:45 AM
      |   view attached

    Hi Harveyysip,

     

    Look at the copied coa profile you create. Looks like you have the attribute "Tunnel-Private-Group-ID=1"  is in place there, the vlan has not been part of the coa profile.

     

    Also be sure your switch config is ok, did you have accounting enabled in your switchconfig like this:

    • radius-server host 172.16.10.3 dyn-authorization
    • aaa accounting network start-stop radius

    accounting is also important from 6.7.x because its managed your concurrent licensing, else licences keep up for 24hr.;)

     

    your mac-auth-all service profile looks good to me.

     

    see attachment some screenshots from my test enviorment.

     

    Hope this help you

     

     

     

    Attachment(s)

    pdf
    Untitled.pdf   333 KB 1 version


  • 9.  RE: Issue - COA enforcement profile never send to NAS

    Posted Jul 12, 2018 06:17 AM

    Hi Mkk,

     

    I already adjusted the attribute.and enabled accounting but I still get the same error and Radius_CoA still failed. can you share to me your full CLI config?

     

     

    TIA :)