I do not. But do I have many customers in the higher ed space.
What's wrong with open networks? Why not use OWE? Does Captive Portal satisfy your requirements? Aren't the applications all encrypted anyways? What access does the student receive when they login with their credentials? Is it more than just internet only? Is there access to internal resources?
Original Message:
Sent: May 19, 2025 10:56 AM
From: wareynolds
Subject: Error 9002 & MSCHAP
I can only assume you don't work in Higher Ed. :-)
What we're really talking about here is network access-regardless of whether the network is protected or open. Due to regulatory requirements and internal policy, we don't want users connecting via open networks; we want access to be authenticated.
If you'd like a more detailed explanation, feel free to DM me.
That said, I appreciate that you asked the question instead of simply stating that these devices shouldn't be allowed on a protected network. Many of us didn't design the networks we inherited, and while we might prefer a more modern or secure architecture, transitioning to that ideal setup is often not feasible in the short term-or it's already underway, but takes time.
So while it's helpful to discuss why certain practices may not be ideal (especially for those who may not know), we still need to address the question as it stands today.
Walt
Original Message:
Sent: May 19, 2025 09:05 AM
From: ahollifield
Subject: Error 9002 & MSCHAP
Why are you allowing unknown/unmanaged/untrusted devices to connect to the protected network?
Original Message:
Sent: May 15, 2025 08:23 AM
From: carriv
Subject: Error 9002 & MSCHAP
Sure. We are doing EAP-TLS, but not for the employees personal devices that we do not manage.
So, there is no setting or tweak we can do to separate this AD auth errors from 9002 error code?
Original Message:
Sent: May 14, 2025 10:33 AM
From: Herman Robers
Subject: Error 9002 & MSCHAP
Don't use MSCHAP in production. Move to EAP-TLS or TEAP.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
Original Message:
Sent: May 14, 2025 09:37 AM
From: carriv
Subject: Error 9002 & MSCHAP
ClearPass's assignment of Error Code 9002 to both certificate/EAP rejections and general authentication failures (like MSCHAP or AD errors) is confusing. Error 9002 commonly points to certificate or EAP problems, whereas Error Code 216 is specifically for authentication failures. Is there a way to isolate MSCHAP/AD errors from the broader 9002 error code? I need to create authorization enforcement rules based on MSCHAP errors, but the fact that 9002 covers multiple possibilities makes accurate enforcement impossible.
Thanks