Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

802.1x Wired clients re-auth every 30 seconds under certain circumstances

This thread has been viewed 6 times
  • 1.  802.1x Wired clients re-auth every 30 seconds under certain circumstances

    Posted Nov 03, 2017 12:39 PM

    I'm setting up CPPM for my company, and so far it's working exactly like I wanted. If we log in with a domain joined machine using a domain user everything works exactly like you expect- they authenticate and the session is left open. If you log in with a domain joined machine with a LOCAL user (ex- local administrator account, authenticated via the Local Users database in CPPM) the computer re-authenticates every 30 seconds on the dot. This introduces some latency and in some cases even dropped packets if the computer takes a while to authenticate successfully.

    How do I fix this issue?



  • 2.  RE: 802.1x Wired clients re-auth every 30 seconds under certain circumstances

    EMPLOYEE
    Posted Nov 03, 2017 12:43 PM

    What type of switch? It's likely related to a switch misconfiguration.



  • 3.  RE: 802.1x Wired clients re-auth every 30 seconds under certain circumstances

    Posted Nov 03, 2017 12:46 PM

    Happens on our Avaya ERS3500s as well as our older HP 1910/3com 2928 switches.

     

    If it was a switch misconfiguration wouldn't the same behavior happen for Domain Computer/Domain user?



  • 4.  RE: 802.1x Wired clients re-auth every 30 seconds under certain circumstances
    Best Answer

    EMPLOYEE
    Posted Nov 03, 2017 12:50 PM

    Good point. Is the supplicant configured manually or via GPO?

     

    Also, it may be better to reach out to your Aruba partner. It is very difficult to troubleshoot stuff here.



  • 5.  RE: 802.1x Wired clients re-auth every 30 seconds under certain circumstances

    Posted Nov 03, 2017 12:56 PM

    The supplicant is configured via GPO. 

     

    I actually tweaked the supplicant/server timeout settings on the switch and I think you were on to something. I changed the port's Supplicant Timeout/Server Timeout setting to 300 seconds and was able to say connected for 5 minutes. Which, of course, begs the question of why the same behavior isn't displayed with DomainMachine/DomainUser logins. 

     

    Thanks for the assistance!