Controllerless Networks

 View Only
last person joined: yesterday 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

Problems with Guest Access

This thread has been viewed 21 times
  • 1.  Problems with Guest Access

    MVP
    Posted Jul 21, 2021 03:06 AM
    Hy everbody,

    I previously successfully created the services for Guest Access and MAC Authentication in the CPPM. Everything was working fine. Users were redirected to the captive portal and were able to create an account an login.

    But approximately one week ago, the behaviour changed: when a user connects, the MAC Authentication Service is used, and the Deny Access Profile is assigned. I think the problem is, that the role "Other" is assigend instead of "Guest", but I can´t find a reason, why the "Guest" role isn´t assigned.

    Any thoughts?

    Knd regards,
    Matthias

    ------------------------------
    Matthias Pohl
    ------------------------------


  • 2.  RE: Problems with Guest Access

    MVP EXPERT
    Posted Jul 21, 2021 03:37 AM
    My first thought is that, if CPPM Services haven't changed and you are completing MAC Auth...is the Private Addressing/MAC Randomisation causing an issue? Do you have a screenshot of your Role Mapping/Enforcement Profile which determines whether Other or Guest is assigned?

    ------------------------------
    Craig Syme
    ------------------------------



  • 3.  RE: Problems with Guest Access

    MVP
    Posted Jul 21, 2021 04:47 AM
    This is the Role Mapping

    ------------------------------
    Matthias Pohl
    ------------------------------



  • 4.  RE: Problems with Guest Access

    EMPLOYEE
    Posted Jul 21, 2021 05:36 AM
    For unknown/new devices, that are not subject to MAC Caching, that is expected. Please check in the Endpoint Repository for the MAC address connecting, if there is the attribute 'Guest Role ID' and if it is set to 2.

    If the attribute is not there, check in your Webauth service if it is set.

    You could check this video how the workflow should work...

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: Problems with Guest Access

    MVP
    Posted Jul 22, 2021 09:22 AM
    I found the cause of my problem:

    I´ve changed the port on the switch, where the IAP is connected. The new port is configured for mac-authentication. On the old port I´ve directly assigned the VLANs. On the new port the IAPs is correctly recognized and the correct VLANs are assigned, but the clients connected to the IAP don´t get an IP address. So it´s not a problem with the GuestAccess, it´s a problem with the port configuration or the service in CPPM

    ------------------------------
    Matthias Pohl
    ------------------------------