Wireless Access

 View Only
last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Clearpass authentication logs

This thread has been viewed 30 times
  • 1.  Clearpass authentication logs

    Posted Jan 18, 2023 01:06 AM
    We have syslog logging for our clearpass server.
    Recently we noticed that there is alot of errors from clearpass
    how do i check who/what devices are causing this?
    Our AP are now under Aruba Central, there is no on-premise controller.



  • 2.  RE: Clearpass authentication logs

    Posted Jan 19, 2023 04:41 AM

    Did you checked the access tracker on clearpass side?

    It seem's this is an message related to GUI logon on ClearPass itself.



    ------------------------------
    Best regards, mom
    ------------------------------



  • 3.  RE: Clearpass authentication logs

    EMPLOYEE
    Posted Jan 26, 2023 11:06 AM
    That is the computer account that is created during the 'join domain' of your ClearPass server.
    It may be that someone disabled or deleted the account, and if you don't do PEAP authentication, you can leave the ClearPass from the domain

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 4.  RE: Clearpass authentication logs

    Posted Jan 26, 2023 08:58 PM
    the username and remote device actually refers to my clearpass server hostname.
    it is currently not in my AD, either as username or computer name.
    i can only see the hostname in my DNS server.
    the logging has since stopped since i power down the clearpass server for 12 hrs last thursday.


  • 5.  RE: Clearpass authentication logs

    EMPLOYEE
    Posted Jan 27, 2023 05:46 AM
    The ClearPass is likely joined to the domain, and if you don't see it in AD, your AD admin probably deleted the computer account and that results in the logs you shared.

    Then also it's logical that if you power off the ClearPass server that the messages disappear. If you want to use the ClearPass server, go in Administration -> Server Configuration -> select your appliance -> Use the Leave Domain button to remove the domain membership of ClearPass:

    If you use PEAP authentication against your AD, that is likely to fail, but it's supposed to be failing already if the account in AD has been removed.

    Please work with your local Aruba partner as they may be able to explain all better than I can; they probably know your deployment as well.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------