Security

 View Only
last person joined: 22 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Port is blocked by port-access

This thread has been viewed 46 times
  • 1.  Port is blocked by port-access

    Posted Dec 04, 2023 07:11 AM

    Hi,

    I have problem with mac-auth some devices, like roger access control device, or unmanaged switch.

    After enabling mac auth on port, port is immediately going to state "Port x/x/x is blocked by port access". Device is not trying to authenticate in clearpass. Only when i disable mac auth on port, port is unblocked.

    Switch is Aruba 6200F.



  • 2.  RE: Port is blocked by port-access

    EMPLOYEE
    Posted Dec 04, 2023 08:05 PM

    the general behaviour is that the port should go into "blocked by port-access" and waits for the device to be ready and then does the MAC auth to ClearPass, then depending on the outcome of the authentication, "show port-access client detail" gives more info on it.

    But if the MAC auth is successful then the port will be unblocked.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: Port is blocked by port-access

    Posted Dec 05, 2023 06:20 AM

    But that device is not trying to authenticate, so i have nothing on that port in "show port-access clients detail"




  • 4.  RE: Port is blocked by port-access

    EMPLOYEE
    Posted Dec 05, 2023 04:30 PM

    what is your interface configuration?



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 5.  RE: Port is blocked by port-access

    Posted Dec 06, 2023 02:40 AM




  • 6.  RE: Port is blocked by port-access

    EMPLOYEE
    Posted Dec 06, 2023 10:00 PM

    is clearpass sending back a local user role?



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 7.  RE: Port is blocked by port-access

    Posted Dec 07, 2023 05:18 AM

    No, there is no information about requesting access in Access Tracker, it looks like device is not trying to authenticate.




  • 8.  RE: Port is blocked by port-access

    Posted Dec 07, 2023 09:56 AM

    What does the command: "show port-access clients interface 4/1/15 detail" tell?

    And does the device that you connect send traffic? Some (rare) devices don't send any traffic when they are connected to the network. Authentication will happen only on the first data packet sent by a client.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 9.  RE: Port is blocked by port-access

    Posted Dec 08, 2023 09:21 AM

    What can i do if that device is not sending any trafic?




  • 10.  RE: Port is blocked by port-access

    Posted Dec 08, 2023 10:26 AM

    Then you can't authenticate is... but if it doesn't send traffic, what is the purpose of the device? What is it for a device?



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 11.  RE: Port is blocked by port-access

    EMPLOYEE
    Posted Dec 09, 2023 06:56 PM

    is it one of those silent devices that only respond to certain incoming traffic?



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 12.  RE: Port is blocked by port-access

    Posted Dec 12, 2023 03:47 AM

    I think yes, one device is roger devices, which is used to access control, i think that device only request to server requests, and thats the only traffic.