Security

last person joined: 10 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

(215 Error) EAP-PEAP: fatal alert by client - access_denied TLS session reuse error

This thread has been viewed 53 times
  • 1.  (215 Error) EAP-PEAP: fatal alert by client - access_denied TLS session reuse error

    Posted Jul 15, 2019 05:50 PM

    We are getting the 215 error w/ devices that are going from our new SSID to the old SSID. Has anyone experienced this issue and have a solution for the problem. I'm leaning toward a certificate issue. Please help....

     

    (215 Error) EAP-PEAP: fatal alert by client - access_denied TLS session reuse error



  • 2.  RE: (215 Error) EAP-PEAP: fatal alert by client - access_denied TLS session reuse error

    EMPLOYEE
    Posted Jul 16, 2019 06:42 AM

    Check whether radius certificate installed in CPPM is valid and  it is supported by windows machine and also check network profile of your machine whether check server cert option is enabled or not?

     

     



  • 3.  RE: (215 Error) EAP-PEAP: fatal alert by client - access_denied TLS session reuse error

    Posted Jul 18, 2019 12:27 PM

    The public certificate is valid, it should be supported by windows machines. We are currently migrating from old CP to new CP and upgrading controllers as well as creating a new SSID. We do have "
    verify the server's identity by validating the certificate" checked. 



  • 4.  RE: (215 Error) EAP-PEAP: fatal alert by client - access_denied TLS session reuse error

    EMPLOYEE
    Posted Jul 18, 2019 07:15 PM

    What is the EAP method (EAP-PEAP or EAP-TLS)?

     

    Ensure,

    the ClearPass Radius certificate is installed with complete chain,

    and the Root CA that signed the radius certificate is marked as the trusted anchor in the wired/wireless supplicant profile, if you observer failure only on Windows Client.

     

    Enable debug for the Radius server and check the debug logs from the Access Tracker for more details.

    To enabled Debug: Administrator >> Server Manager >> Log Configuration >> Select Service >> Radius Server.



  • 5.  RE: (215 Error) EAP-PEAP: fatal alert by client - access_denied TLS session reuse error
    Best Answer

    Posted Jul 25, 2019 12:15 PM

    This issue has been resolved. It was a group policy issue with unchecked trusted root certificate. Thank you for everyones help