Wireless Access

 View Only
last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

wireless 802.1X service re-authentication

This thread has been viewed 19 times
  • 1.  wireless 802.1X service re-authentication

    Posted Oct 07, 2021 11:53 AM
    We're seeing hourly re-authentications in clearpass hitting our wireless 802.1X service. Anyone else seen this behavior and know the cause/solution?

    This is only occurring to one of our offices. Have mobility master managing a pair of mobility controllers for each office, with Aruba/HPE switches and Clearpass appliance at each located in a cluster. 


    ------------------------------
    Matthew Stogsdill
    ------------------------------


  • 2.  RE: wireless 802.1X service re-authentication

    EMPLOYEE
    Posted Oct 07, 2021 12:11 PM
    See if it is on a timer:

    (Babarella2) #   show user ip 192.168.1.248 | include reauth
    This operation can take a while depending on number of users. Please be patient ....
    phy_type: a-VHT-40, l3 reauth: 0, BW Contract: up:0 down:0, user-how: 1
    Timers: L3 reauth 0, mac reauth 0 (Reason: ), dot1x reauth 0 (Reason: )
    Number of reauthentication attempts: mac reauth 0, dot1x reauth 0​


    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------



  • 3.  RE: wireless 802.1X service re-authentication

    MVP EXPERT
    Posted Oct 07, 2021 12:56 PM
    Silly question but your not sending a session timeout of 3600 back from ClearPass are you for access accepts from that controller?

    Also on the controller normally there’s a default session timeout of 1 day ( lots of seconds) perhaps that was changed to 3600


    a




  • 4.  RE: wireless 802.1X service re-authentication

    Posted Oct 07, 2021 01:14 PM

    The session timer is set to 1 day or rather 24 hours. The radius response is not asking the Mobility Controller to reauthenticate. I had checked the Mobility masters and mobility controller to see if reauthentication was enable but it is set to disable.