Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

unable to ping across vlans without 'ip helper-address' command

This thread has been viewed 1 times
  • 1.  unable to ping across vlans without 'ip helper-address' command

    Posted Feb 17, 2016 11:00 AM

    This SEEMS the best place to put this, but if necessary, please feel free to move it. 

     

    The Setup:

    In my environment I have a 3400 controller in production and a ClearPass appliance in production. The 3400 has sub-interfaces in the primary(server/appliance) vlan(7), the management vlan(11), and each separate vlan that SSIDs and the APs(24-29) themselves reside on. the ClearPass appliance resides on a separate vlan (23). The ClearPass appliance is used for RADIUS authentication, and is reachable from a wireless device, or any wired device, other than our guest SSID, which is ACL'ed off.

     

    I also have a 7205 controller which is being configured to eventually be the production controller. I have a second ClearPass appliance that is doing RADIUS and 'other NAC stuff' for the 7205 APs. The connections fall into the exact same vlans as the production controller/ClearPass/APs/SSIDs. 

     

    The Problem:

    Devices connected to the 7205 cannot reach the ClearPass appliance. Example: A laptop is placed on an SSID on the 3400 and recieves an IP of a.b.c.6, and can ping ClearPass. the same laptop disconnects, and reconnects to an SSID on the 7205, recieving an IP of a.b.c.10. The device can no longer ping the ClearPass device. I have - I believe - ruled out a role-acl issue by putting an allowall acl on the role on the 7205.

     

    I added an ip helper-address on the SSID interface of my core to point to the IP address of the ClearPass appliance, and now pings go through properly. However, it is my understanding that this is effectively allowing broadcasts to go through the layer 3 interface into the helper-address. 

     

    The Question:

    Why does the 7205 require a helper-address, when the 3400 does not? The only difference I can see is that the 3400 is in bridged mode, and the 7205 (required for captive-portal and posturing I am told) is in tunnel mode.

     

    Thanks,

     

    Russell



  • 2.  RE: unable to ping across vlans without 'ip helper-address' command

    EMPLOYEE
    Posted Feb 17, 2016 11:27 AM

    What is the default gateway of network  a.b.c.10.?  That would be responsible for the routing.  That is where you should start.



  • 3.  RE: unable to ping across vlans without 'ip helper-address' command

    Posted Feb 17, 2016 12:12 PM

    in both cases, the device gets it's DHCP address from the 6509 core, and the default gateway is a.b.c.1

     



  • 4.  RE: unable to ping across vlans without 'ip helper-address' command

    EMPLOYEE
    Posted Feb 17, 2016 12:28 PM

    But is .1 the 6509?



  • 5.  RE: unable to ping across vlans without 'ip helper-address' command

    Posted Feb 17, 2016 09:56 PM

    yes. Please note that anything on vlan 24 that ISN'T coming from a device connected to the an AP on the 7205 can access the ClearPass appliance without the ip helper-address statements. Even the 7205 itself, with an extended ping sourced from the vlan 24 subinterface can ping the ClearPass appliance.

     

    Russell



  • 6.  RE: unable to ping across vlans without 'ip helper-address' command

    EMPLOYEE
    Posted Feb 17, 2016 10:18 PM

    We would have to see your toplogy as well as a tech support of the controller to understand everything that is going on.  Right now, we would be just guessing what is wrong...



  • 7.  RE: unable to ping across vlans without 'ip helper-address' command

    Posted Feb 18, 2016 10:23 AM

    attached. Let me know if more clarification is needed

    Attachment(s)

    txt
    7205 tech-support.txt   2.18 MB 1 version


  • 8.  RE: unable to ping across vlans without 'ip helper-address' command

    EMPLOYEE
    Posted Feb 18, 2016 10:51 AM

    I don't see any  users on the 7205.  What VLAN what role do users get when they connect and they see this issue?

     



  • 9.  RE: unable to ping across vlans without 'ip helper-address' command

    Posted Feb 18, 2016 11:51 AM

    Vlan 24 and a role of authenticated.

     

    Russell



  • 10.  RE: unable to ping across vlans without 'ip helper-address' command

    EMPLOYEE
    Posted Feb 20, 2016 09:09 AM

    It does not make sense that this would be blocked.  There is probably something else at play.  You should open a TAC case.