Wireless Access

Reply
Contributor II
Posts: 44
Registered: ‎04-06-2011

Aruba OS upgrade 6.1.3.10 and L2 Authentication Fail Through

Hello,

This morning we upgraded from ArubaOS 6.1.3.3 to 6.1.3.10.  We have two M3 / 6000 controllers setup in a redundant master configuration.

One of our SSIDs is WPA2/PSK and uses MAC authentication ( MAC Caching ) with a captive portal on an Amigopod 3.9 appliance.  Users connecting to this SSID who already have a MAC account on the Amigopod have no problems.   Any new users fail MAC auth ( which is normal ) and should be redirected to the web captive portal for authentication.  Since the code upgrade, they are rejected access, and don't see the web captive portal and eventually fail to connect to the SSID.  The Amigopod shows a normal access-reject because it can't find a MAC account, but it looks like the controller isn't failing back to the captive portal web-auth.

I looked around at things and I saw the "L2 Authentication Fail Through" setting in the AAA Profile ( unchecked).  I enabled it and it seemed to restore normal operation.

 

Is having it enabled a valid setting for a  WPA2/PSK / Captive Portal / MAC Auth setup?  We have had this unchecked for more than a year while we were on 6.1.3.3 and things were working ok -- just curious what may have changed in the new code.




Thanks,
Bryan

Aruba
Posts: 233
Registered: ‎11-19-2009

Re: Aruba OS upgrade 6.1.3.10 and L2 Authentication Fail Through

L2 Authentication fail through is basically to peform let`s say both MAC authentication and 802.1x authentication.

Say for example, when MAC auth fails, enable the L2-auth-fail-through to do the 802.1x auth.

 

See below info from User-guide.

 

l2-auth-fail-through.jpg

This config is not going to be applicable just for MAC auth /Captive portal.

 

You can open up a support case where TAC could try to replicate your config  on 6.1.3.10 to see if the same issue occurs.

 

 

Thank you

 

 

 

Search Airheads
Showing results for 
Search instead for 
Did you mean: