Controllerless Networks

 View Only
  • 1.  Clients are reverting to SSID role after some minutes

    Posted Jan 03, 2025 01:25 PM

    Hi there,

    Currently facing an issue where some clients will receive a role from ClearPass (aruba-user-role VSA), apply it but after some minutes get into the SSID role.

    There is no activity on ClearPass other than Accounting-Stop and Accounting-Start (with a new session-id) when this happens. No Access-Req is present.

    1. Client connects; ClearPass answers with aruba-usr-vsa = user-role; IAP shows role = user-role for the client
    2. Then, after some minutes, client role becomes equal to the SSID name
    3. Disconnecting the client (trashcan icon in client list) forces a new reauth and the role gets again equal to user-role
    4. But then again after some minutes ir reverts back to SSID name

    Any idea what can be the issue here?

    Thanks



  • 2.  RE: Clients are reverting to SSID role after some minutes

    Posted Jan 03, 2025 06:46 PM
    Edited by ariyap Jan 03, 2025 06:46 PM

    does this happen to only a specific user-role? perhaps there is a spelling error. I suggest to delete that user role on the IAP and recreate it.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: Clients are reverting to SSID role after some minutes

    Posted Jan 06, 2025 02:34 AM

    Could it be that you have Role Assignment in your SSID configuration? It may be that there is a role assignment that for specific device types changes the role, that may happen in the middle of the session. I would make sure there are no VLAN Assignment Rules and no Role Assignment Rules to start with. Then just use the Aruba VSAs: Aruba-User-Role and Aruba-User-VLAN, which are both applied even if there are no assignment rules.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 4.  RE: Clients are reverting to SSID role after some minutes

    Posted Jan 06, 2025 09:34 AM

    Hi,

    Unfortunately not.

    Whatever option I chose for "role assignment", it always show the same behaviour.




  • 5.  RE: Clients are reverting to SSID role after some minutes

    Posted Jan 06, 2025 10:05 AM

    Are you doing anything with a CoA that could be causing the issue?

    Open a case with TAC, if the issue is consistently repeatable then setting up a debug session to figure out where the change is happening pretty easily.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 6.  RE: Clients are reverting to SSID role after some minutes

    Posted Jan 06, 2025 10:15 AM

    No CoAs involved.

    Currently in contact with TAC, but still no solution was provided.




  • 7.  RE: Clients are reverting to SSID role after some minutes

    Posted Jan 06, 2025 05:03 PM

    Do you see this behaviour immediately using CLI on the IAP? also check the output of "show log user 20" and "show log sec 20" for clues. 



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------