Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Why client authentication failed when fail over from master to local controller?

This thread has been viewed 1 times
  • 1.  Why client authentication failed when fail over from master to local controller?

    Posted Jun 10, 2016 04:00 AM

    Hi, we have 2 controllers which are configured as master and local, and use clearpass to do client authentication. LMS IP /backup lms IP are already set in AP system profile. Master and local controllers are all added to Clearpass as network devices. Now when AP connected to master controller, the authentication successful, but when connect to local controller, all client cannot be authenticated, and no incoming authentication request is received on ClearPass. Please advise the possible cause. Thanks.



  • 2.  RE: Why client authentication failed when fail over from master to local controller?

    EMPLOYEE
    Posted Jun 10, 2016 04:02 AM
    #1 reason:. You don't have the second controller configured as a radius client in clear pass...


  • 3.  RE: Why client authentication failed when fail over from master to local controller?

    Posted Jun 10, 2016 04:14 AM

    Thanks for reply.

     

    Yeah, we considered this possible cause.  We have added the second controller on Clearpass under "configuration/network device" as the first controller. Anything is needed to be configured for second controller on clearpass?  



  • 4.  RE: Why client authentication failed when fail over from master to local controller?

    EMPLOYEE
    Posted Jun 10, 2016 04:21 AM
    You should look in the event viewer in clear pass to get a clue why it is happening.


  • 5.  RE: Why client authentication failed when fail over from master to local controller?

    Posted Jun 10, 2016 04:28 AM

    The procedure to add second controller IP on Clearpass is just need to add the controller under "Configuration/Network device" , right? Now there is nothing in Clearpass "Access Tracer". Later We will check the event view. Thanks a lot



  • 6.  RE: Why client authentication failed when fail over from master to local controller?

    EMPLOYEE
    Posted Jun 10, 2016 07:02 AM
    The event viewer will tell you if it is dropping a radius request because the traffic is coming from the wrong IP address. Access tracker will not tell you anything


  • 7.  RE: Why client authentication failed when fail over from master to local controller?

    Posted Jun 11, 2016 09:52 PM
    Hi,

    What information you see in controller from system and errorlogs?

    How about show auth trace output?