Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all
This thread has been viewed 3 times
  • 1.  Virtual IP

    Posted Jan 12, 2017 02:52 AM

    Hi!

     

    I´m wondering if it is possible to change clearpass VRRP-id. It seems that the default is vrrp-id 1. This causes a issue at a customer site, since they have a different product using vrrp-id 1. Nothing serious but it creates a lot of log entrys on the other product regarding auth fail (they try to speak to eachother using different password).

     

    I can find nothing about changing this looking through different documentations. 



  • 2.  RE: Virtual IP

    EMPLOYEE
    Posted Jan 12, 2017 06:59 AM
    ClearPass does not use VRRP. Please open a TAC case to try and isolate the problem.


  • 3.  RE: Virtual IP
    Best Answer

    EMPLOYEE
    Posted Jan 12, 2017 06:59 AM
    ClearPass does not use VRRP. Please open a TAC case to try and isolate the problem.


  • 4.  RE: Virtual IP

    Posted Jan 12, 2017 07:02 AM

    Well thats strange, everytime I turn of virtual IP the logging stops on the device. Must be something that interferes, they are on the same vlan.

     

    I will check with TAC.

     

    Thanks



  • 5.  RE: Virtual IP

    Posted Jan 15, 2017 02:15 PM

    Just to confirm, we use UCARP on CPPM for our VIP functionality.



  • 6.  RE: Virtual IP

    Posted Jan 17, 2017 04:05 AM

    Thanks!

     

    It seems that you shouldn´t use the same ID in CARP as VRRP if they exist on the same subnet. I would suggest adding a option to change VHID from the gui in clearpass from default to avoid issues for customers using both vrrp and CARP on the same subnet.

     

    From: https://doc.pfsense.org/index.php/CARP_Configuration_Troubleshooting

     

    Conflicting VHIDs

    The VHID determines the virtual MAC address used by that CARP IP. The input validation in pfSense will not permit using conflicting VHIDs on a single pair of systems, however if there are multiple systems on the same broadcast domain running CARP, it's possible to create a conflict. VRRP also uses the same virtual MAC address scheme, so a VRRP IP using the same VRID as a CARP IP VHID will also generate the same MAC address conflict.

    When using CARP on the WAN interface, this also means VRRP or CARP used by the ISP can also conflict. Be sure to use VHIDs that are not in use by the ISP on that broadcast domain.