Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Client get wrong User role after Authentication

This thread has been viewed 14 times
  • 1.  Client get wrong User role after Authentication

    Posted Feb 09, 2018 02:51 AM

    Hi all,

    I have a problem with an Open SSID. After authenticated, my client always get "authenticated user role" even though AAA  profile is correct.

    Any one can help me fix this issue?

     

    Many Thanks for help.

     



  • 2.  RE: Client get wrong User role after Authentication

    EMPLOYEE
    Posted Feb 09, 2018 03:10 AM

    You should type "show user ip <ip address of user>" to see how it got its role.



  • 3.  RE: Client get wrong User role after Authentication

    Posted Feb 10, 2018 11:20 AM
      |   view attached

    @cjosephwrote:

    You should type "show user ip <ip address of user>" to see how it got its role.


    Hi Colin,

    The output show role is authenticated, but i don't know how my client receive that role.  I've already used "show reference" for that role and i see that none of my AAA profile in used.

    Anyway, i'm very appreciate for your help.

     

     

    Attachment(s)

    txt
    Show user ip.txt   5 KB 1 version


  • 4.  RE: Client get wrong User role after Authentication
    Best Answer

    EMPLOYEE
    Posted Feb 10, 2018 09:53 PM

    Mac authentication from a Radius VSA:

    Authentication: Yes, status: started, method: MAC, protocol: PAP, server: NSRP-Clearpass
    Role Derivation: ROLE_DERIVATION_MBA_VSA
    VLAN Derivation: MBA MSFT Attributes
    mac auth server: NSRP-Clearpass, dot1x auth server: N/A


  • 5.  RE: Client get wrong User role after Authentication

    Posted Feb 12, 2018 11:03 AM

    Hi Colin,

    So, client get wrong role possible cause by policy on AAA server ?

    I am treating leg injuries so i can't check it now :). I will check it as soon as possible then report to you the result.
    Many thanks for help. 

     



  • 6.  RE: Client get wrong User role after Authentication

    EMPLOYEE
    Posted Feb 12, 2018 11:46 AM

    The client got its role as the result of mac authentication.

    If you are sending an Aruba-User-Role attribute back in your mac authentication response from your radius server, that is what is changing the role.



  • 7.  RE: Client get wrong User role after Authentication

    Posted Feb 21, 2018 05:49 AM

    Hi Colin,

    You're right, my client get its role as the result of an attribute on clearpass. I've already removed it.

     

    Thank for your support.