Security

 View Only
  • 1.  Error 9002 & MSCHAP

    Posted May 14, 2025 09:38 AM

    ClearPass's assignment of Error Code 9002 to both certificate/EAP rejections and general authentication failures (like MSCHAP or AD errors) is confusing. Error 9002 commonly points to certificate or EAP problems, whereas Error Code 216 is specifically for authentication failures. Is there a way to isolate MSCHAP/AD errors from the broader 9002 error code? I need to create authorization enforcement rules based on MSCHAP errors, but the fact that 9002 covers multiple possibilities makes accurate enforcement impossible.

    Thanks



  • 2.  RE: Error 9002 & MSCHAP

    Posted May 14, 2025 10:34 AM

    Don't use MSCHAP in production. Move to EAP-TLS or TEAP.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Error 9002 & MSCHAP

    Posted May 15, 2025 08:23 AM

    Sure. We are doing EAP-TLS, but not for the employees personal devices that we do not manage. 

    So, there is no setting or tweak we can do to separate this AD auth errors from 9002 error code?




  • 4.  RE: Error 9002 & MSCHAP
    Best Answer

    Posted May 16, 2025 12:00 PM

    Check the Auth method you have for MSChap and see if it has a number of retries set.  This is set at 3 by default.  I ran into an issue where a user was putting in a bad password and based on that setting clearpass would try again.  Many times the client would not respond so it was listed as a timeout.  I set that to 0 and many of the timeouts went to error code 216 after that.

    There are still to may timeouts in my opinion.  I am not buying that this is certificate issues as I will get devices that both authenticate and timeout randomly.  Latest one is a managed machine that is not moving and will time out.




  • 5.  RE: Error 9002 & MSCHAP

    Posted May 16, 2025 01:51 PM

    Thank you so much. That bit of information you provided is exactly what I was looking for. Now I can better sort out devices actually causing a bad logon versus another type of timeout. 

    By the way, I have seen machines that goes onto sleep kind of mode and EAP timeouts around this sleep event. No necessary certificates issues.

    Thanks again for your insight. 




  • 6.  RE: Error 9002 & MSCHAP

    Posted 28 days ago

    Why are you allowing unknown/unmanaged/untrusted devices to connect to the protected network?




  • 7.  RE: Error 9002 & MSCHAP

    Posted 28 days ago

    I can only assume you don't work in Higher Ed. :-)

    What we're really talking about here is network access-regardless of whether the network is protected or open. Due to regulatory requirements and internal policy, we don't want users connecting via open networks; we want access to be authenticated.

    If you'd like a more detailed explanation, feel free to DM me.

    That said, I appreciate that you asked the question instead of simply stating that these devices shouldn't be allowed on a protected network. Many of us didn't design the networks we inherited, and while we might prefer a more modern or secure architecture, transitioning to that ideal setup is often not feasible in the short term-or it's already underway, but takes time.

    So while it's helpful to discuss why certain practices may not be ideal (especially for those who may not know), we still need to address the question as it stands today.

    Walt




  • 8.  RE: Error 9002 & MSCHAP

    Posted 28 days ago

    I do not. But do I have many customers in the higher ed space.

    What's wrong with open networks? Why not use OWE? Does Captive Portal satisfy your requirements? Aren't the applications all encrypted anyways? What access does the student receive when they login with their credentials? Is it more than just internet only? Is there access to internal resources?