Security

last person joined: 23 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

WLC and Clearpass MAC authentication

This thread has been viewed 4 times
  • 1.  WLC and Clearpass MAC authentication

    Posted Sep 22, 2014 10:03 AM

    Hello,

    my goal is that if an account is valid for 3 days, the guest have to authenticate with username and password only the first time, for the others authentication the Clearpass should verify only the MAC that has saved the first time and after 3 days clears this MAC entry so the guest have to renew his account.

    i have configured the Guest access with mach caching, but seems that is not works.

     

    When the client try to connect for the first time, he is redirected to Captive Portal and the account is created.
    But when try to disconnect and reconnect the captive portal is shown again.

     

    In the Tab monitoring of ClearPass I can not see any attempt of MAC Authentication... seems that the request doesn't match the service rule

     

    Rule:
    Connection client MAC address equals "%{Radius:IETF:User-Name}"

    can you help me?

     

    thanks in advance

    Best regards

    Andrea


  • 2.  RE: WLC and Clearpass MAC authentication

    Posted Sep 22, 2014 11:47 AM

    Are you using an Aruba controller ?



  • 3.  RE: WLC and Clearpass MAC authentication

    Posted Sep 22, 2014 11:53 AM

    Hello,

    no, i'm using a CISCO WLC.

     

    regards

    Andrea



  • 4.  RE: WLC and Clearpass MAC authentication

    Posted Sep 22, 2014 12:04 PM

    Do you have Mac filtering enabled under your Layer 2 tab and then enable On MAC filter failure under the layer 3 tab ?

     

     



  • 5.  RE: WLC and Clearpass MAC authentication

    Posted Sep 23, 2014 09:33 AM

    Hello,

    yes i have done this configuration.

     

    Andrea.



  • 6.  RE: WLC and Clearpass MAC authentication

    EMPLOYEE
    Posted Sep 23, 2014 09:35 AM

    What format is your controller sending the MAC address for the username?



  • 7.  RE: WLC and Clearpass MAC authentication

    Posted Sep 23, 2014 09:38 AM

    i can choose it...

    what is the correct format?

     

     



  • 8.  RE: WLC and Clearpass MAC authentication

    Posted Sep 23, 2014 10:25 AM

    As cappalli suggested you can take a look at the format is sending the mac address in the request under Security > Mac filtering

     

    2014-09-11 11_52_45-P3-DC-WLC.png

     

    Another thing you should consider doing is setting the reject delay to 0 , i noticed some issues if this wasn't use this value:

    2014-09-23 10_14_27-ClearPass Policy Manager - Aruba Networks.png



  • 9.  RE: WLC and Clearpass MAC authentication

    Posted Sep 24, 2014 06:32 AM

    Thanks,

    i'll check this and update you.



  • 10.  RE: WLC and Clearpass MAC authentication

    Posted Sep 25, 2014 08:25 AM

    Hello,

    i'm tried to modify the value.. but have the same issue...

     

    some idea?

     

    thanks in advance

    Best regards

    Andrea



  • 11.  RE: WLC and Clearpass MAC authentication

    Posted Sep 25, 2014 09:29 AM

    Did you created the Mac caching services using the templates ?



  • 12.  RE: WLC and Clearpass MAC authentication

    Posted Oct 06, 2014 04:51 AM

    Yes.



  • 13.  RE: WLC and Clearpass MAC authentication

    Posted Oct 12, 2014 07:07 AM

    i would double check the Cisco WLC config, are you sure the MAC auth section is enabled. if you are sure try to confirm this with a packet capture. if it is just not send then this is a Cisco WLC issue and you could probably better check with their forum / support.



  • 14.  RE: WLC and Clearpass MAC authentication

    Posted Oct 12, 2014 03:50 PM
    What version of CP are you on? Earlier versions of CP ignores requests and didn't show them in Access Tracker, but in 6.4 you will find them there as long as something is received from the Controller.

    Format of the MAC-address sent from the controller doest matter, unless you are specifically testing for something like "client-mac-address-dash".. I believe Clearpass normalizes before using it in the sql check towards endpoint db.

    A thing to check..
    There is a dropdown on the Cisco WLC (I think under Security/Mac-"something") that defaults to client ip-address. Change that to "Client mac-address".

    If you post some screenshots of your configuration on both the WLC and CP we should be able to narrow it down more.

    I'm working with the exact same setup these days so if you're unable to get it working I can post some more details with screenshots if needed.


  • 15.  RE: WLC and Clearpass MAC authentication

    Posted Oct 13, 2014 05:05 AM

    Hello,

    i'm using a clearpass 6.3.5.

    On the WLC i think that is all correct, i have followed a tech-guide released by aruba.

     

    Unfortunately today i'dont have access to clearpass, but  If you can give me some screenshot of your configuration i can do a check with mine configuration, because i remember how it is configured.

     

    Best regards

    Andrea Acampa



  • 16.  RE: WLC and Clearpass MAC authentication

    Posted Oct 13, 2014 05:05 AM

     

    Security -> AAA / MAC Filtering. Radius Compatibility Mode.

      -> Set this to Cisco ACS

     

    Security -> AAA / Radius -> Authentication -> Call Station ID Type

      -> Set this to "System MAC Address"

     

     



  • 17.  RE: WLC and Clearpass MAC authentication

    Posted Oct 13, 2014 01:49 PM

    Hi John,

    about:

     

    Security -> AAA / Radius -> Authentication -> Call Station ID Type

      -> Set this to "System MAC Address"

     

    there is "Call Station ID Type 1" and "Call Station ID Type"

     

    i also see on the option: "MAC Delimiter" they use "Colon"

     

    am i ok?

    regards.



  • 18.  RE: WLC and Clearpass MAC authentication

    Posted Oct 13, 2014 12:29 AM
    Andrea,

    What do you have set as your authentication sources?
    You need to allow all Mac address if this is for an open said.