Wireless Access

 View Only
last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Can't change VLAN on macauth

This thread has been viewed 50 times
  • 1.  Can't change VLAN on macauth

    Posted May 07, 2021 01:16 PM

    Hi,
    I have the following problem with macauth + clearpass:

    - I have a role that redirects to captive with VLAN 100
    - I have a role when the user registers that goes to VLAN 200
    - User connects, gets into VLAN 100 and into captive
    - User registers, Clearpass sends CoA and the device reconnects and gets a role with VLAN 200 (I can see this on access tracker)
    - But the devices keeps connected to VLAN 100. I need to manually disconnect and reconnect. Sending Bounce CoA or Terminate Session does not fix this. Renew DHCP also doesn't.

    The controller seems to stick the device to the initial VLAN it receives, and does not change it during the session.
    Only after disconnect-reconnect.

    Any idea how to fix?

    Thanks



    ------------------------------
    Ricardo Duarte
    ------------------------------


  • 2.  RE: Can't change VLAN on macauth

    Posted May 07, 2021 02:37 PM

    Just to clarify, is this for Wireless, or for a wired connection? Vendor?



    ------------------------------
    Christopher Wickline
    ------------------------------



  • 3.  RE: Can't change VLAN on macauth

    Posted May 07, 2021 02:42 PM
    Hi,

    Wireless with Aruba controllers (AOS 8.6.0.9) + CAP.

    Regards

    ------------------------------
    Ricardo Duarte
    ------------------------------



  • 4.  RE: Can't change VLAN on macauth

    Posted May 07, 2021 03:54 PM
    Uhmm...
    It seems to be a problem with iOS.

    Because when I click "renew lease" nothing happens.

    Tried with a macOS device and everything seems to work.

    ------------------------------
    Ricardo Duarte
    ------------------------------



  • 5.  RE: Can't change VLAN on macauth

    EMPLOYEE
    Posted May 07, 2021 04:04 PM
    Have you tried, in your enforcement profile, responding with an Aruba-User-Vlan attribute, instead of trying to set the VLAN in the role?

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------



  • 6.  RE: Can't change VLAN on macauth

    EMPLOYEE
    Posted May 08, 2021 03:21 AM

    The controller may be caching the initial role it picked up.  Try this and do for all roles it may pick up.

    user-role <name>
    registration-role

    ------------------------------
    Michael Clarke (Aruba)
    ------------------------------



  • 7.  RE: Can't change VLAN on macauth

    Posted May 08, 2021 03:23 PM
    Hi Michael,

    While this seems not to fix the issue, it was a great call that I was not aware and will use for my registration roles :)

    But in this particular case the root cause seems to be related with Apple iOS. macOS and Windows are working fine, and they can transition from roles with different vlans without an issue.
    But Apple iOS "renew dhcp" seems not to work.  Even when I manually click "renew lease" under the Wifi network I don't see any DHCP traffic going to my dhcp servers.  Not sure where the DHCP traffic is getting lost. It's either on the iPhone or the controller. Nothing else is involved.

    Regards.

    ------------------------------
    Ricardo Duarte
    ------------------------------



  • 8.  RE: Can't change VLAN on macauth

    Posted May 09, 2021 02:58 AM
    I usually encounter such a behavior when I forget to add RFC 3576 CoA server ip address on the ssid aaa profile on controller or when I select wrong vendor for NAD device on Clearpass. 

    Best, Gorazd

    ------------------------------
    Gorazd Kikelj
    ------------------------------



  • 9.  RE: Can't change VLAN on macauth

    Posted May 14, 2021 05:34 PM
    Not that.
    RFC 3576 CoA is working fine.

    ------------------------------
    Ricardo Duarte
    ------------------------------



  • 10.  RE: Can't change VLAN on macauth

    Posted May 15, 2021 01:59 AM
    Hi RIcardo.

    Did you receive any error or warning in Access Tracker Accounting tab for these authentications?
    If there is something wrong with RADIUS response, it will usually shown as NAD device error in accounting record. Like for example nonexisting (read mistyped) vlan that is pushed to the switch.

    Best, Gorazd

    Edit: I was too fast. You are only sending the role to the controller and controller will do the rest. I did have similar problem but Aruba Wireless Bounce port resolve it for me. 
    ------------------------------
    Gorazd Kikelj
    ------------------------------