Wired Intelligent Edge

 View Only
last person joined: yesterday 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

ClearPass/2930F will not bounce port

This thread has been viewed 58 times
  • 1.  ClearPass/2930F will not bounce port

    Posted Feb 23, 2021 08:34 PM
    Hi

    I am trying to test MAC Auth for wired devices. ClearPass should profile the device and then bounce the port. What I am finding, is that ClearPass is correctly profiling the device and adding it to Endpoint but doesn't bounce the port. If I manually bounce the port on the switch, the device is applied the correct role on the switch.

    The following is a summary of the configuration:
    - Both ClearPass and the switch are running the same NTP server
    - The switch is running WC.16.10.0005 and ClearPass is 6.9.0.130064
    - The switch's vendor name in ClearPass is Aruba
    - The profiler has [ArubaOS Switching - Bounce Switch Port] set
    - The switch has dyn-authorization and time-window 0 set

    Is there anything else I should be checking?


  • 2.  RE: ClearPass/2930F will not bounce port

    Posted Feb 27, 2021 08:20 PM
    Check that both ClearPass and the swith are using NTP.

    Faced multiple times that kind of issues and it was because of the time difference.

    ------------------------------
    Gaston Gabas
    ------------------------------



  • 3.  RE: ClearPass/2930F will not bounce port

    Posted Mar 01, 2021 01:46 AM
    Thanks for responding. Yes both devices are on the same NTP server and I checked that their time is in sync.


  • 4.  RE: ClearPass/2930F will not bounce port

    Posted Mar 01, 2021 01:37 AM
    Check if the device you are trying to bounce is the right vendor in clearpass, remember the aruba switch is hpe vendor, think the aruba vendor is for access points

    ------------------------------
    Morten Johannsen
    ------------------------------



  • 5.  RE: ClearPass/2930F will not bounce port

    Posted Mar 01, 2021 01:48 AM
    HPE isn't an option in my version of clearpass.


  • 6.  RE: ClearPass/2930F will not bounce port

    Posted Mar 01, 2021 01:52 AM
    Hewlett-Packard-Enterprise is a vendor

    ------------------------------
    Morten Johannsen
    ------------------------------



  • 7.  RE: ClearPass/2930F will not bounce port

    Posted Mar 01, 2021 02:04 AM
    These are the options that I get. Do I need to so anything to enable HPE?




  • 8.  RE: ClearPass/2930F will not bounce port

    Posted Mar 01, 2021 02:09 AM
    Hi again, iv had the problem, and my fix was under the configuration - network - device, there you can enable Radius coa and what port



    ------------------------------
    Morten Johannsen
    ------------------------------



  • 9.  RE: ClearPass/2930F will not bounce port

    Posted Mar 01, 2021 06:00 PM
    Hi.

    Yes I originally had it set to Hewlett-Packard-Enterprise but it still only gave me Aruba Switch port bounce, nothing for HPE.


  • 10.  RE: ClearPass/2930F will not bounce port

    EMPLOYEE
    Posted Mar 03, 2021 05:58 AM
    Can you, from Access Tracker, do a Change Status and you should be able to select CoA and have the ArubaOS Switching actions:

    If you see different actions here, the Vendor is not set to Hewlett Packard Enterprise in the Network Device definition, and also the options you see here are the only ones you can (should) select in the profiler action tab.

    Also, if there is a failure you can see the failure reason when manually triggering the CoA. First make sure that manual CoA is successful, only after that try the automatic response in Profiling.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------



  • 11.  RE: ClearPass/2930F will not bounce port

    Posted Mar 22, 2021 12:12 AM
    Hi.

    Sorry for the slow reply. I think I have the switch and profile tab set correctly but I can't do a CoA from the Change Status page.

    If I go to Change Status from Access Tracker, I only see the following:


    The Network Device Vendor Name is set to Hewlett-Packard-Enterprise:


    The RADIUS CoA Action on the Profiler tab is set as follows:



    Thanks.



  • 12.  RE: ClearPass/2930F will not bounce port

    EMPLOYEE
    Posted Mar 22, 2021 05:05 AM
    Ok, in that first screenshot of change status you should be able to see the RADIUS CoA option first.

    Have you enabled accounting in your switch? That may be required and you should see the 'Accounting' tab in Access Tracker.
    If you have accounting enabled, and see the Accounting tab in Access Tracker and still don't see RADIUS CoA as an option, can you check if Insight is enabled from the Server Configuration, and enable it if it isn't? I don't think Insight is a requirement, but it's one of the first things I turn on for additional visibility/reporting.

    It may be a good point to reach out to Aruba TAC Support if you still can't make it work, we must be missing something very basic.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------