Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Action needed to connect after resuming from Sleep/Hibernation

This thread has been viewed 1 times
  • 1.  Action needed to connect after resuming from Sleep/Hibernation

    Posted May 26, 2018 06:47 PM

    Hi all


    I have an Aruba environment with CAP, RAP, Controller 6.5 and Clearpass 6.7. There are users using Linux, MAC OS and Windows.


    The Windows 10 users are facing a inconvenient task to click on SSID to connect on network after resuming from Sleep/Hibernation. (8 or 24hours)

     

    The network is configured to authenticate devices by 802.1X EAP-PEAP.

    The workstations trust at enterprise root CA. The certificate used by Clearpass was signed by this enterprise root CA.

     

    I opened a TAC Case and they advise to use a Public valid certificate to fix it. Does it make sense?

     

    Do you have any tip to improve the user experrience?

     

    Thank you,

     

    Ed

     

     



  • 2.  RE: Action needed to connect after resuming from Sleep/Hibernation

    EMPLOYEE
    Posted May 26, 2018 06:52 PM

    I don't think that a public certificate would help.  Typically it is the client that decides that it will reconnect, and that is a client setting.  If your radius certificate is issued by your domain and users pass authentication, the client should be able to reconnect.  If it does not, you need to turn on debugging on the controller and search for the client's mac address in access tracker to see why it cannot connect.  The client should have the SSID defined and set to connect to automatically.  If it is, you should turn on debug logging for that client on the controller and look at the access tracker to see if the client is even trying.



  • 3.  RE: Action needed to connect after resuming from Sleep/Hibernation

    Posted May 26, 2018 07:03 PM

    Hi cjoseph,

     

    The user debug log was collected for theses users when the resuming from sleep mode.

    The four way handshake is done with sucess -> <- and the first radius packet is droped *.

    Because of that the TAC suspected the certificate.

     

     



  • 4.  RE: Action needed to connect after resuming from Sleep/Hibernation

    EMPLOYEE
    Posted May 26, 2018 07:44 PM

    I did not see any of the logs, so that is just my general opinion.  There are many environments that function with a private domain CA that don't have this problem, is the only reason for my post.