Security

 View Only
  • 1.  CX switch - deleting a failed DUR

    Posted 16 days ago

    Got a small issue with a CX switch and downloadable user roles

    I created a radius group called CPPM_RADIUS which should. have had 2 FQDNs relating to CPPM VIPS in it. Unfortunately it also had  the ip addresses of the cppm. VIPS in there before the FQDNs.

    I also have the command

    aaa accounting port-access start-stop interim 900 group CPPM_RADIUS

    So when. the switch tries to download the DUR, its downloading  it from an IP address and not a FQDN and fails

    a show port-access roles  shows that its failed because  Server  Certificate Invalid.

    The server cert has a CN of cppm.x.y and. a number of SANs as defined in the radius. group. Using  the ip address results in the CN being returned which doesnt have ethe ip address in it.

    Cant delete the DUR

    Tried deleting the IP addresses from the group .. .caching somewhere so its still generting the same error

    Tried creating another group CPPM_NAC with correct settings  and adjusting the  above accounting command to  use that group .... sill happens.

    Short of rebooting the switch stack, how can i force the switch to  download a version ? ( guess could make a small change at cppm, but  that would get pushed to the CX estate 



  • 2.  RE: CX switch - deleting a failed DUR

    Posted 16 days ago

    Normally the switch retries to download the XML file that contains the data. However, I think you might hit this issue (fixed in 10.13.1050 / 10.14.1010 / 10.15.0005).

    Can you try the workaround?

    https://arubanetworking.hpe.com/techdocs/AOS-CX/Consolidated_RNs/HTML-6300-6400/Content/10_15/0005/fixes.htm

    Symptom: A client fails to get access to the network after successful authentication.

    Scenario: This issue can impact a client trying to onboard with a downloadable role after temporary network issues.

    Workaround: Log off all the clients that are with the Downloadable User Role (DUR) in the failed state using command port-access log-off client role <role-name>. This will initiate a retry of download of the role. 



    ------------------------------
    Willem Bargeman
    Systems Engineer Aruba
    ACEX #125
    ------------------------------



  • 3.  RE: CX switch - deleting a failed DUR

    Posted 16 days ago
    And it worked ! Many thanks 
    FYI switch running 10.13.1080

    Another question
    If you are using a captive portal DUR, do you have to enable something on the switch to get it to work? 
    On os-s you have to enable captive-portal

    Have a CX DUR that's supposed to push a device into our captive portal vlan but no logs as to why it doesn't work 
    A
    Sent from my iPhone





  • 4.  RE: CX switch - deleting a failed DUR

    Posted 15 days ago

    No that's not needed. What is needed on the switch is explained in the documentation.



    ------------------------------
    Willem Bargeman
    Systems Engineer Aruba
    ACEX #125
    ------------------------------