Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass : wired EAP-TLS : Somes devices timeout with first authentication

This thread has been viewed 15 times
  • 1.  Clearpass : wired EAP-TLS : Somes devices timeout with first authentication

    Posted 2 days ago

    Hi,

    We have several timeouts with somes devices with wired EAP-TLS authentication. These timeouts appears only the first day of the week when the post is connected to the network. 

    In logs, we can see that after few Access-Challenge, the client stop to respond and the authentication go to timeout.

    We just need to disconnect and reconnect the cable and the authentication works without any problem all the week.During the weekend, the device is turned off.

    We are trying to recover as much information as possible on the workstation side but seems different models with different networks cards. These are all Windows 10 laptop. 

    This is only a small amount of devices (may be 5% of the inventory). All our devices are managed with Intune (CSP for EAP-TLS authentication).

    I already found a post with a timeout problem each beginning of the week without solution.

    Have you ever had this problem? Do you have some debug ideas?

    Thanks



  • 2.  RE: Clearpass : wired EAP-TLS : Somes devices timeout with first authentication

    Posted yesterday

    Is that user authentication, or machine authentication?

    What types of switches do you have, and what EAP/retry timers, MacAuth fallback?



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Clearpass : wired EAP-TLS : Somes devices timeout with first authentication

    Posted yesterday
    Hi Herman Robers,
     
    We use machine authentication.
     
    We have 6300 OS CX switches (JL661A version FL.10.10.1080).
    For timers, I don't find any specific configuration, so I think the default timers.
    Yes, we have MacAuth fallback, so the PC go to block VLAN (MAC unknown).
     
    Thanks.



  • 4.  RE: Clearpass : wired EAP-TLS : Somes devices timeout with first authentication

    Posted yesterday

    Machine authentication with client certificates (EAP-TLS) is expected to work reliably. If the computers are booting up, or coming back from sleep, there may be delays, like when the supplicant is starting. If you see the client falling back to MAC authentication, it may help to configure concurrent onboarding on the switch port to keep the 802.1X process running also after a MAC authentication.

    Another option to try is to disable Session resumption in your EAP-TLS Authentication Method.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: Clearpass : wired EAP-TLS : Somes devices timeout with first authentication

    Posted 6 hours ago

    Hi Herman Robers,

    Thanks for your answers. 

    We will try to isolate some ports and enable "port-access onboarding-method concurrent enable" on it.

    In second time, we will try to disable Session resumption.

    Just need to wait Monday to confirm the solution.