Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

session logs for RADIUS requests. sometimes are empty.

This thread has been viewed 3 times
  • 1.  session logs for RADIUS requests. sometimes are empty.

    Posted Jan 28, 2014 02:53 PM

    I am seeing an odd thing with the session logs on my ClearPass deployment.

    When I open up the details window for a RADIUS Request and click the show logs button, sometimes the logs are there and sometimes they are not. When the log is missing, a message saying "No Logs for this Session".

     

    Other RADIUS requests from the same service are present.

     

    Anyone know why this is happening?



  • 2.  RE: session logs for RADIUS requests. sometimes are empty.

    EMPLOYEE
    Posted Jan 28, 2014 03:41 PM

     If something was processed, something should be there.  What was the exact result of the request? 



  • 3.  RE: session logs for RADIUS requests. sometimes are empty.

    Posted Jan 29, 2014 07:20 AM

    It does not seem to matter what the result of the request is it happens for both REJECTS and ACCEPT.  In the case of accepted authentications the role mappings and policies are being replied and the correct VSAs are being returned to the controllers.

     

    I am trying to figure out if the requests which have no logs are all on the same node in the cluster or perhaps from the same wireless controller.



  • 4.  RE: session logs for RADIUS requests. sometimes are empty.

    Posted Jan 29, 2014 09:17 AM

    Did a little more poking around and it seems that the older the RADIUS request, the greater the likelihood the log will be missing.

    If I look at requests from 12 hours ago, they are almost all gone but the most recent requests are all intact.

     

     



  • 5.  RE: session logs for RADIUS requests. sometimes are empty.

    EMPLOYEE
    Posted Jan 29, 2014 05:43 PM

    Is this after a certain date you are seeing this? Remember there is a setting in the cluster wide properties that allow you to retain the data longer. Just remember that can fill up the HD space if you are running in debug or you have a lot of clients connecting or reconnecting. 

     

    sessionlog.png



  • 6.  RE: session logs for RADIUS requests. sometimes are empty.

    Posted Jan 30, 2014 07:48 AM

    My Cleanup intervals are all set to the defaults so I should see logs for 7 days.

    If I go back 24 hrs. the logs from the previous day are missing for certain.

    As far as I can tell the threshold is 12 hrs.  If I look at sessions from 11hrs ago the logs are still there.

     



  • 7.  RE: session logs for RADIUS requests. sometimes are empty.
    Best Answer

    EMPLOYEE
    Posted Jan 30, 2014 10:14 AM
    Please open a TAC case so they can look into it


  • 8.  RE: session logs for RADIUS requests. sometimes are empty.

    Posted Jan 28, 2014 04:01 PM

    What version of ClearPass do you have installed ?



  • 9.  RE: session logs for RADIUS requests. sometimes are empty.

    Posted Jan 29, 2014 07:22 AM

    Running version 6.2.4.5 appliance with 1 publisher and 1 subscriber.



  • 10.  RE: session logs for RADIUS requests. sometimes are empty.

    EMPLOYEE
    Posted Jan 29, 2014 07:41 AM

    We see this on 6.2.4 as well.