Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

profiling with coa doesnt work

This thread has been viewed 0 times
  • 1.  profiling with coa doesnt work

    Posted Oct 17, 2017 06:55 AM
    Hi all,
    I have an issue with profiling using coa. My coa works fine, it can disconnect users after allowing the user to do a dhcp process. But i have an issue where in my endpoint, the user endpoint category wont get updated. It's like the option55 doesnt get forwarded to the clearpass or my clearpass cannot read it.
    I tried to sniff the dhcp process and i can confirm thr option55 is there in the request.
    All happens in same subnet so firewall should not be an issue.
    I need an idea what i have to check. Kinda stuck here. Thanks in advance.


  • 2.  RE: profiling with coa doesnt work

    Posted Oct 17, 2017 08:14 AM
    One more thing, the access switch is the dhcp server, both wlc and switch already has helper address to clearpass.


  • 3.  RE: profiling with coa doesnt work

    EMPLOYEE
    Posted Oct 17, 2017 09:16 AM

    Look at this from the perspective of not profiling. Don't bring in CoA to this yet as an issue or part of it. Is anything profiling in ClearPass? 



  • 4.  RE: profiling with coa doesnt work

    EMPLOYEE
    Posted Oct 17, 2017 09:31 AM
    Many switches will not relay if the the server is in the same subnet.


  • 5.  RE: profiling with coa doesnt work

    Posted Oct 17, 2017 05:17 PM
    Hi Seth, let say it doesnt. What do i check?

    Hi Tim. I use 2960. It works in my lab and i only restore everything to my customer poc environment. The different is just the 2960 the dhcp server now.


  • 6.  RE: profiling with coa doesnt work
    Best Answer

    Posted Oct 18, 2017 12:28 AM

    found the workaround.

    seems like i cannot run the access switch that forwarding ip helper as dhcp server.

    when i remove dhcp server config from the switch and put it on other devices, profiling works just fine. probably just a bug on switch side. i am using 15.2(2)E7