Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Captive portal re-authentication when the user moves to new MC on AOS 8.

This thread has been viewed 3 times
  • 1.  Captive portal re-authentication when the user moves to new MC on AOS 8.

    Posted Jan 27, 2019 01:29 AM

    Hi,

    I have 3 MC on the network. The client move from MC1 -> MC2 -> MC3. It's will redirect to the captive portal to authenticate.

    Can I fix this problem about the captive portal authentication when the client moves to other MC

    Cluster Connection Types: L2 Connected
    3 MC on Clusters
    AOS 8.3.0.5
    Redundancy: Enable
    AP Load Balancing: Enable



  • 2.  RE: Captive portal re-authentication when the user moves to new MC on AOS 8.

    EMPLOYEE
    Posted Jan 27, 2019 09:33 AM

    The user should never move to another MC in a cluster.  It always should remain on the same controller, no matter what access point it roams to.

     

    On the MM, the command 

    show global-user-table list

    should show you what controller a user is on.  It should not change, in a cluster.  If your user has to reauthenticate, your cluster might be misconfigured.



  • 3.  RE: Captive portal re-authentication when the user moves to new MC on AOS 8.

    EMPLOYEE
    Posted Jan 27, 2019 09:48 AM

    SSH into any controller in your cluster and type "show lc-cluster group-membership" to see if they are fully clustered.



  • 4.  RE: Captive portal re-authentication when the user moves to new MC on AOS 8.

    Posted Jan 27, 2019 10:20 AM

    I have checked the cluster as below. I think it fully clustered. Any another point to check this problemshow lc-cluster.jpg



  • 5.  RE: Captive portal re-authentication when the user moves to new MC on AOS 8.

    EMPLOYEE
    Posted Jan 27, 2019 10:50 AM

    I would turn on user debugging for that user at the cluster level to understand why the user is being returned to the captive portal.

     

    config t

    logging level debugging user-debug <mac address of user>

    You would then do "write mem" on the MM

     

    SSH into the MD with the user on it and type "show log user-debug all" to see why the user is being returned to the logon role 



  • 6.  RE: Captive portal re-authentication when the user moves to new MC on AOS 8.

    Posted Jan 30, 2019 04:47 AM
      |   view attached

    Hi,

     

    I have test again by walking around my office to check this problem. It does not occur if the client is in coverage of WiFi signal.
    The client will re-authentication when out of WiFi coverage. I have attached debug log.

     

    The idle timer change to 0 sec when client out of coverage.

    Jan 30 16:10:12 authmgr[4019]: <522234> <5221> <DBUG> |authmgr| Setting idle timer for user d0:c5:f3:18:90:71 to 0 seconds (idle timeout: 900 ageout: 1000).

    How I can fix this problem?

     

    Attachment(s)

    txt
    log-dis.txt   9 KB 1 version