Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Need assistance with 620 and Authentication Times Extended

This thread has been viewed 0 times
  • 1.  Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 12:03 PM

    Just started managing a new customer's site, and they have a 620 running the wireless.

    Customer has requested that 2 of the 3 profiles/accounts used to access (One is Corp, Other is Guest and then Tenant) allow the end user to keep the ability to leave the network and return to the site without having to sign back in or authenitcate.

     

    Being new to the Aruba, any help would be greatly appreciated.

     

    Thanks



  • 2.  RE: Need assistance with 620 and Authentication Times Extended

    EMPLOYEE
    Posted Jun 04, 2012 12:10 PM

    What type of authentication are they using?

     



  • 3.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 12:16 PM

    Appears to be AAA, with a 802.1X.



  • 4.  RE: Need assistance with 620 and Authentication Times Extended

    EMPLOYEE
    Posted Jun 04, 2012 12:18 PM

    802.1x meaning WPA/2-PSK?   How do they connect?  The supplicant on the device, after waking up, should try to reconnect them, typically.

     



  • 5.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 12:20 PM

    Should be just the WPA/s-PSK. Kind of stunmbling around the Aruba, as I am more fluent with Cisco.

     



  • 6.  RE: Need assistance with 620 and Authentication Times Extended

    EMPLOYEE
    Posted Jun 04, 2012 12:21 PM

    If the users are using a single preshared key to connect, when they come back to their devices, they should attempt to connect back to the network by themselves.

     

    What exactly is happening?

     



  • 7.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 01:51 PM

    Yeah, the customer has a preshared key used by guests.

    When the device sits idle and/or leaves the network, they are prompted to re-enter the key.

     

    Customer wants the timeout/return to be around 7 days.

     

     



  • 8.  RE: Need assistance with 620 and Authentication Times Extended

    EMPLOYEE
    Posted Jun 04, 2012 01:54 PM
    What devices are those? It should just reconnect. The controller cannot force a prompt for a PSK. It is the supplicant on the device that would do that.


  • 9.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 02:00 PM

    Thinkind it is Apple related.

     



  • 10.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 02:18 PM

    Being told that it is all devices.

    Laptops once they go to sleep are prompting the visiting users to re-enter the pre-shared key.

     



  • 11.  RE: Need assistance with 620 and Authentication Times Extended

    EMPLOYEE
    Posted Jun 04, 2012 02:26 PM
    Please open a case so someone cab work with you on this. It does not seem typical.


  • 12.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 02:41 PM

    Even if there is no current maintenance contract?

     



  • 13.  RE: Need assistance with 620 and Authentication Times Extended

    EMPLOYEE
    Posted Jun 04, 2012 02:48 PM

    Well, that would not be an option, then.

     

    We can try to troubleshoot it here, but coordination to figure out what is going on could be very painful and time consuming.

     



  • 14.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 02:56 PM

    Possibly just a bug in the current running version on the equipment?

    Partiion 0 is 5.0.2.0

    Partition 1 is 5.0.4.3

     



  • 15.  RE: Need assistance with 620 and Authentication Times Extended

    EMPLOYEE
    Posted Jun 04, 2012 02:58 PM

    I will let others chime in.  I have never seen that.

     



  • 16.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 03:01 PM

    It does not happen to 1 of the 3 built profiles.

    I do believe it was configured that way, as I am sure of the mindset of the Engineer that set them up intialy.

     



  • 17.  RE: Need assistance with 620 and Authentication Times Extended

    EMPLOYEE
    Posted Jun 04, 2012 03:05 PM

    How many wireless networks are being broadcast?

     



  • 18.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 03:08 PM

    3

     



  • 19.  RE: Need assistance with 620 and Authentication Times Extended

    EMPLOYEE
    Posted Jun 04, 2012 03:09 PM

    What kind of authentication and encryption is in play for those other two networks?



  • 20.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 03:11 PM

    They should all be the same.

    Only difference is assigned IPs and preshared Key.

     



  • 21.  RE: Need assistance with 620 and Authentication Times Extended

    EMPLOYEE
    Posted Jun 04, 2012 03:22 PM

    @kmcintosh78 wrote:

    They should all be the same.

    Only difference is assigned IPs and preshared Key.

     


    What role does the users who have the problem get?

     



  • 22.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 03:27 PM

    Not really sure of the question.

    There are basically 3 networks being broadcast.

    Corp

    Guest

    Tenant.

     

    All are on there own Pre-shared Key. Authentication and Encryption is the same thoughout I believe.

    Main difference is that the Corp network gets an internal IP in the 10.x.x.x network and does not get prompted to re-enter the Pre-shared key once the device either sleeps and/or leaves the network and returns.

     

    The Guest and Tenant networks are getting prompted to re-enter the pre-shared key every time the device sleeps or leaves the network. Almost just a timeout setting. IPs I believe are in the 192.168.x.x network.



  • 23.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 03:40 PM

    I have never seen a pre-shared key be automatically "forgotten" unless they didn't check the little button that says "remember this network" or something like that (assuming these are Macs).

     

    If you enter the key correctly and check that box, when the device comes out of sleep or standy or boots fresh, it will automatically reconnect without needing to do anything.

     

    This all assumes a preshared key network.  If they are hitting a web page (captive portal), that's a whole different issue.

     

    Go to the GUI and click on Configuration > AP Configuration > <appropriate AP group name> > Virtual APs > SSID Profiles > Guest or Tentant.

     

    What is the authentication?



  • 24.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 03:43 PM

    Ok, I do believe it is a captive portal.

    Again, I am new to the Aruba Controllers. AP as a whole. More Route/Switch/Firewall, not wireless.

     

    Let me check it.

     



  • 25.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 03:49 PM

    Yep, I was incorrect.

    The Guest and Tenant is set for Captive Portal.

     

    So, how do I change these requirements, if possible?

     



  • 26.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 03:57 PM

    There is an idle timeout under Configuration > Authentication > Advanced, but it can only be set up to 255 minutes.

     

    If you want to make that time longer, you will have to do some type of MAC caching using a RADIUS server.  Aruba sells ClearPass Policy Manager that can accomplish this.



  • 27.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 03:59 PM

    It is currently set at 300 seconds, it also has the ability to go from seconds to minutes.

     

     



  • 28.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 04:03 PM

    It is for the "Authentication Timers" "User Idle Timeout"

     

    "Authentication Server Dead Time" is set for 10 minutes.



  • 29.  RE: Need assistance with 620 and Authentication Times Extended
    Best Answer

    Posted Jun 04, 2012 04:16 PM

    User Idle Timeout is the setting you want.  You can set it to seconds or minutes, but the most is 255 minutes (15300 seconds).



  • 30.  RE: Need assistance with 620 and Authentication Times Extended

    Posted Jun 04, 2012 04:22 PM

    Got it. Thanks so much guys.