Higher Education

last person joined: 16 days ago 

Got questions on how to enable mobility in education? Submit them here!
Expand all | Collapse all

Clearpass Problem

This thread has been viewed 3 times
  • 1.  Clearpass Problem

    Posted Oct 07, 2013 12:40 AM

    Hello all,

     

    Can all of you share problem after deploy Aruba Clearpass at your enviroment (education enviroment),I need a information from you all if there have similar problem at my place,so if have same problem,so you all can share the solution with me.Thank You.



  • 2.  RE: Clearpass Problem

    Posted Oct 07, 2013 01:22 PM

    You refer to "similar problem". What problem are you having?



  • 3.  RE: Clearpass Problem

    Posted Oct 07, 2013 10:31 PM
      |   view attached

    Thank you for your concern,

     

    I have problem after deploy clearpass at my place,here I list the problem:

     

    1. Already connected to onboard ssid,but no landing page (onboard page ) appear.Sometime it can be direct but sometime failed to direct to right landing page.

     

    2. User need to do the onboard authentication step 2 time (first time failed),after do the second time,the user can connected to the internet.

     

    3. Error to the radius.Here I attach the error at our place.

     

    Hope you have a solution of my problem,we already contact the Aruba support but still not solve the problem. I have no idea how to solve the problem,we already do the troubleshoot but the problem still occur.



  • 4.  RE: Clearpass Problem

    EMPLOYEE
    Posted Oct 07, 2013 11:16 PM

    #1 Make sure you have a TAC case open.

     

    #2 Is this a VM or hardware, and the Size of the CPPM? Is there a cluster? How many Users/Devices auth?

    #3 What Wired and wireless vendors and firmware are you using?

     

    #4 see below inline.

    -----------------------------

    @noorsyazwan wrote:

    Thank you for your concern,

     

    I have problem after deploy clearpass at my place,here I list the problem:

     

    1. Already connected to onboard ssid,but no landing page (onboard page ) appear.Sometime it can be direct but sometime failed to direct to right landing page.

     

    Troy: Are you seeing this on one type of device or on all types (IOS, Windows, MAC, ETC) If its IOS are you using the CNA bypass?

     

    2. User need to do the onboard authentication step 2 time (first time failed),after do the second time,the user can connected to the internet.

     

    Troy: Is this a constant issue or just once in a while? What is the processor load on the system? Is this production or lab?

     

    3. Error to the radius.Here I attach the error at our place.

     

    Troy: Are the users local or remote. What is the ping between the device and CPPM.  Also what is access tracker showing when the user auths?

     

    Hope you have a solution of my problem,we already contact the Aruba support but still not solve the problem. I have no idea how to solve the problem,we already do the troubleshoot but the problem still occur.


    Without looking at the system. My first guess would be a connectivity issues between the device and CPPM.

     

    All the issues you are listing rely on a strong conection and low latency. I would try to running a few auth test between the NAS devices and CPPM. Double check the clocks on the NAS devices, AD, and CPPM.  Try doing a wired test to see if you have the same issue.

     

    This is just a small list of things to test and there are many more but I would start with one issue, Run packet captures and ping test and work from there.

     

     

     

     



  • 5.  RE: Clearpass Problem

    Posted Oct 08, 2013 12:07 AM
      |   view attached

    1. Already connected to onboard ssid,but no landing page (onboard page ) appear.Sometime it can be direct but sometime failed to direct to right landing page.

     

    Troy: Are you seeing this on one type of device or on all types (IOS, Windows, MAC, ETC) If its IOS are you using the CNA bypass?

     

    Wan: Effect at laptop (windows & mac),mobile device don't have a problem

     

    2. User need to do the onboard authentication step 2 time (first time failed),after do the second time,the user can connected to the internet.

     

    Troy: Is this a constant issue or just once in a while? What is the processor load on the system? Is this production or lab?

     

    Wan: Sometime,I mean from 10 device it will effect 7-8 device,load of cppm server is CPU: 4% and Mem Util: 26%.Production enviroment.Whole campus.

     

    3. Error to the radius.Here I attach the error at our place.

     

    Troy: Are the users local or remote. What is the ping between the device and CPPM.  Also what is access tracker showing when the user auths?

     

    Wan: It local user. We not allow our user ping our server.So we cannot ping when the user already connected.Error at the access tracker show "bind as user failed"

     

    Hope I answer some of your question.



  • 6.  RE: Clearpass Problem

    EMPLOYEE
    Posted Oct 08, 2013 12:12 AM
    What version of CPPM?

    What wireless vendor are you using?

    Do you have Airwave?


  • 7.  RE: Clearpass Problem

    Posted Oct 08, 2013 04:17 AM

    What version of CPPM?

    6.1.4

    What wireless vendor are you using?
    Aruba


    Do you have Airwave? Thank You,
     Yes

     

    Thank You

    Syazwan



  • 8.  RE: Clearpass Problem

    EMPLOYEE
    Posted Oct 08, 2013 09:53 PM
    The first thing you need to do is have TAC dig into the bind issue. You need to find out if its a user issue or a thread issue.

    Are you see this during a high activity time or all the time.