Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Authentication records for last 6 months

This thread has been viewed 3 times
  • 1.  Authentication records for last 6 months

    Posted Jun 16, 2015 10:07 AM

    Hi,

    As a security concern, I have to retain the authentication records (username/user IP/User mac/Timestamp) from clearpass atleast for last 6 months. But when i search it on clearpass i could just see upto last few days. I tried pointing the authentication records to a 3rd party syslog server but I am unable to get the proper data. 

    Has anybody tried this ??

     



  • 2.  RE: Authentication records for last 6 months

    EMPLOYEE
    Posted Jun 16, 2015 10:10 AM

    ClearPass keeps 7 days by default. This can be increased but is not recommended in most cases.

     

    Syslog is abolustely supported.

     

    What syslog server are you using? Can you post some screenshots of your syslog export setup?



  • 3.  RE: Authentication records for last 6 months

    Posted Jun 16, 2015 10:21 AM
      |   view attached

    Hi Tim,

    Thanks for the instant response !

    I am temporarily using 3cdaemon syslog server for testing purposes. I tried different column selections but I am unable to get the data which I need.

     



  • 4.  RE: Authentication records for last 6 months

    EMPLOYEE
    Posted Jun 16, 2015 10:41 AM

    What data are you trying to get that's not listed there?

    Or is the issue you're not getting any data in your syslog server?



  • 5.  RE: Authentication records for last 6 months

    Posted Jun 16, 2015 10:48 AM

    I need the clients username, mac address, IP address and the time stamp.

    I do receive data but that is not what i need.

    we need this for copyright infringement cases, to identify the user.



  • 6.  RE: Authentication records for last 6 months
    Best Answer

    EMPLOYEE
    Posted Jun 16, 2015 10:52 AM
    You'll need accounting enabled in order to get the IP with 802.1X.


    Thanks,
    Tim


  • 7.  RE: Authentication records for last 6 months

    Posted Jun 17, 2015 08:54 AM

    I enabled accounting and I am able to get the data but in most of the cases it says "RADIUS.Acct-Framed-IP-Address=null." 

    Below is the sample for the two logs with null and with an IP address !

     

    eg:

    Jun 17 08:36:02 X.X.X.X Jun 17 2015 08:36:00.922 EDT X.X.X.X CEF:0|Aruba Networks|ClearPass|6.5.0.71095|42133-1-0|Session Logs|0|TimestampFormat=MMM dd yyyy HH:mm:ss.SSS zzz RADIUS.Acct-Framed-IP-Address=null Common.Username=dc:86:d8:93:5c:45 Common.Request-Timestamp=2015-06-17 08:34:03-04 Common.Host-MAC-Address=dc86d8935c45 src=X.X.X.X 

    Jun 17 08:36:02 X.X.X.X Jun 17 2015 08:36:00.922 EDT X.X.X.X CEF:0|Aruba Networks|ClearPass|6.5.0.71095|42134-1-0|Session Logs|0|TimestampFormat=MMM dd yyyy HH:mm:ss.SSS zzz RADIUS.Acct-Framed-IP-Address=X.X.X.X Common.Username=dc:86:d8:93:5c:45 Common.Request-Timestamp=2015-06-17 08:34:03-04 Common.Host-MAC-Address=dc86d8935c45 src=X.X.X.X 



  • 8.  RE: Authentication records for last 6 months

    EMPLOYEE
    Posted Jun 17, 2015 08:57 AM

    Mbachhav,

     

    That is because 802.1x authentication occurs before a client gets an ip address, so a radius accounting start is not always aware of what ip address a client receives.  Can you turn on radius interim accounting and see if you get that information?

     

     



  • 9.  RE: Authentication records for last 6 months

    Posted Jun 17, 2015 09:07 AM

    Hi Colin,

    Thanks for the swift response ! Radius intermin accounting is already enabled !

     

    Mohit



  • 10.  RE: Authentication records for last 6 months
    Best Answer

    EMPLOYEE
    Posted Jun 17, 2015 09:13 AM

    What is your interim accounting interval?  You might have to wait 5 minutes to get that information, based on the interval.  Do you see anything in the accounting tab in ClearPass?  See if you see the ip address five minutes later in the tab and in the syslog message.

     

    Syslog messages in ClearPass are not necessarily realtime, so it could take up to 2 minutes after the interim accounting message for it to show up in syslog from ClearPass.

     

     

     

     



  • 11.  RE: Authentication records for last 6 months

    Posted Jun 16, 2015 10:51 AM

    Hi ,

     

    Configuration looks correct. as the work around, take the pkt capture at the Syslog end for at least 15 mins to confirm whether CPPM server pushing the required data.

     

    Please feel free for any further help on this.