Security

last person joined: 20 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Issue when trying to disconnect users.

This thread has been viewed 0 times
  • 1.  Issue when trying to disconnect users.

    Posted Feb 02, 2012 02:01 PM

    everything is working except the disconnect.amigoerror.JPG



  • 2.  RE: Issue when trying to disconnect users.

    Posted Feb 02, 2012 04:12 PM

    This requires RFC3576 to be enabled on your controller - you can check this in your aaa profile in your ArubaOS configuration.



  • 3.  RE: Issue when trying to disconnect users.

    Posted Feb 02, 2012 07:37 PM

    I checked that and still no luck :( aaa.JPG



  • 4.  RE: Issue when trying to disconnect users.

    Posted Feb 02, 2012 07:48 PM

    Are you running in a master local environment with your controllers? It looks like from the error message that the RADIUS request is not getting to the controller in question. Not sure if there are any network topology or firewall constraints that could be preventing this traffic from the Amigopod to the controller.



  • 5.  RE: Issue when trying to disconnect users.

    EMPLOYEE
    Posted Feb 02, 2012 09:34 PM

    I believe you need to be using the management interface IP on Amigopod to get this properly working.



  • 6.  RE: Issue when trying to disconnect users.

    Posted Feb 09, 2012 06:45 AM

     

    I have the same thing, and I believe it's network related in our end. Controller is inside - Amigopod is in dmz.. I see that Radius Acct is sent from Controller and received on Amigopod. Something in the way of allowed initiatior for Radius-Acct being the Controller and not Amigopod. Working with network admin to verify and fix it.

     

     

     

    .. John



  • 7.  RE: Issue when trying to disconnect users.

    EMPLOYEE
    Posted Feb 09, 2012 08:34 AM

    It may be network related or just not having the proper IP.

    In my lab when I first started to play with Aruba-Amigopod I ran into this very issue.  Could not get clients to disconnect.  My lab is a small flat network with no firewalls in between.  The resolution to my issue was that I had configured the Aruba side to point to the LAN interface on Amigopod.  Everything works when using that interface EXCEPT the client disconnect.  When I switched everything over to the Management interface everything worked.  If you are able to do some packet captures take a look at the source IP coming from Amigopod when you disconnect clients.



  • 8.  RE: Issue when trying to disconnect users.

    Posted Feb 10, 2012 11:26 AM

    Please note that the disconnect is based on the RADIUS extension of RFC3576 and therefore uses UDP port 3799 if you are managing firewall policies between the Amigopod and your controller.



  • 9.  RE: Issue when trying to disconnect users.

    Posted Feb 13, 2012 10:59 AM

    Whats the difference between the LAN and MGMT  ?  



  • 10.  RE: Issue when trying to disconnect users.

    EMPLOYEE
    Posted Feb 13, 2012 11:08 AM

    Curious if my solution fixed your disconnect issue.

     

    I do not know what the difference is between the two interfaces.  I was originally told they are identical.  As you can see from my earlier post my experience in my lab says otherwise.

     

    I do know that if you purchase an appliance instead of using the VM image there are two physical ports.  The LAN interface defaults to using DHCP while the Management interface uses static IP.  Otherwise I am not aware of any difference.  Maybe someone else can chime in.



  • 11.  RE: Issue when trying to disconnect users.

    Posted Feb 13, 2012 11:44 AM

    I have not tried it yet - Live environment so I was going to wait untill there were fewer people on the guest network.



  • 12.  RE: Issue when trying to disconnect users.

    Posted Feb 14, 2012 03:10 PM

    There is no technical difference between the two interfacees on Amigopod. You just need to be careful about which interface is carrying the default route for the appliance and make sure this will permit the traffic to the controller. Also be aware that RFC3576 (3799) uses a different port to standard RADIUS (1812,1813) just in case you have some firewall rules inline.