Wireless Access

last person joined: 17 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Blacklist duration

This thread has been viewed 2 times
  • 1.  Blacklist duration

    Posted May 10, 2013 09:36 AM
    One master controller, two locals -- all M3, 6.1.3.2 Blacklist duration is set to 0 for all Virtual APs/SSIDs for both Authentication Failure and Other. Found the bad guy on Local2 and blacklisted him; remaining time is blank as expected. Because you can only use the WebUI to blacklist a connected client, I went to the CLI for Master and Local1 and issued this command: stm add-blacklist-client [mac address]. On both, the remaining time is 1 hour, no matter what I do. Bad guy was able to connect to Local1 last night. Any way to fix this?


  • 2.  RE: Blacklist duration

    EMPLOYEE
    Posted May 10, 2013 10:15 AM

    Set the "ap blacklist-time" parameter which specifies how long unassociated users get blacklisted:

     

    http://community.arubanetworks.com/t5/ArubaOS-and-Mobility-Controllers/Blacklist-Clients-on-3600-controller-ArubaOS-6-1-2-2/td-p/22534

     



  • 3.  RE: Blacklist duration

    Posted May 10, 2013 10:20 AM
    I thought I had set that, which is why I said, "Blacklist duration is set to 0 for all Virtual APs/SSIDs for both Authentication Failure and Other." Are you saying to do that again in the CLI?


  • 4.  RE: Blacklist duration
    Best Answer

    EMPLOYEE
    Posted May 10, 2013 10:22 AM

    (Aruba3600) (config) #ap ap-blacklist-time

     

    That parameter is GLOBAL and not under the virtual AP.  It corresponds to the blacklist time for unassociated clients.

     



  • 5.  RE: Blacklist duration

    Posted May 10, 2013 11:17 AM
    Thanks! I had not read all the way through the link you sent.


  • 6.  RE: Blacklist duration

    Posted Oct 28, 2014 12:10 PM

    When you say GLOBAL, is that "Set it on the Master and the Locals learn it," or "Set it on every controller?"



  • 7.  RE: Blacklist duration

    EMPLOYEE
    Posted Oct 28, 2014 12:27 PM
    Global meaning all SSIDs broadcasting from APs connected to that controller.

    You need to blackilist clients on each controller.


  • 8.  RE: Blacklist duration

    Posted Oct 28, 2014 01:13 PM

    Ah, good point.

    I hadn't thought of that -- I was refering to where I set 'ap ap-blacklist-time 0'

    Is that a Master pushed configuration bit, or will I have to set it on each controller.