Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Bounce port or disconnect request for authenticatetd user (MAC)

This thread has been viewed 16 times
  • 1.  Bounce port or disconnect request for authenticatetd user (MAC)

    Posted Feb 20, 2019 08:23 AM

    Hello,

    I have mac authentication service and it works fine.  

    Now I would like to force the user / device to be re-authenticated. Does clearpass have this functionality or something similar?

    service that parses logs, set the attribute to the user / device and based on the given attribute, I want to assign it to the specific subnet.

    Unfortunately, I have switches without coa support.



  • 2.  RE: Bounce port or disconnect request for authenticatetd user (MAC)

    EMPLOYEE
    Posted Feb 20, 2019 08:26 AM
    For a wired client where a VLAN change is occuring, you need to use a CoA bounce port. If you just need to force a reauthentication, you can use a Disconnect Message or a CoA Reauthenticate Session.


  • 3.  RE: Bounce port or disconnect request for authenticatetd user (MAC)

    Posted Feb 20, 2019 08:32 AM

    Can you explain how to use Disconnect Message?



  • 4.  RE: Bounce port or disconnect request for authenticatetd user (MAC)

    EMPLOYEE
    Posted Feb 20, 2019 08:36 AM
    Not sure what you mean. ClearPass issues a Disconnect Request based on a enforcement policy rule like any other enforcement. You use the Terminate Session enforcement profiles in ClearPass.


  • 5.  RE: Bounce port or disconnect request for authenticatetd user (MAC)

    Posted Feb 20, 2019 09:00 AM

    I do not know how to enforce re-authentication. My switch does not support coa. 

    In that case, I have to create a new Enforcement Profiles (snmp type),  using the reser connection attribute?



  • 6.  RE: Bounce port or disconnect request for authenticatetd user (MAC)

    EMPLOYEE
    Posted Feb 20, 2019 10:58 AM
    Can you please provide details about your switch(es)? Things like vendor, model, code version, etc.


  • 7.  RE: Bounce port or disconnect request for authenticatetd user (MAC)

    Posted Feb 21, 2019 01:38 AM

    HPE 1920-8G-PoE+ Switch JG922A



  • 8.  RE: Bounce port or disconnect request for authenticatetd user (MAC)

    Posted Feb 25, 2019 06:09 AM

    Today I connected procurve 5406zl to clearpass. When I wanted to change the status for the user using coa in Access Tracker.

    After executing the bounce switch port option, it receives a message about the following error:

    cppm.PNG



  • 9.  RE: Bounce port or disconnect request for authenticatetd user (MAC)

    EMPLOYEE
    Posted Feb 25, 2019 06:48 AM
    That's "ArubaOS Wireless". You need to use the one for "ArubaOS Switching".


  • 10.  RE: Bounce port or disconnect request for authenticatetd user (MAC)

    Posted Feb 25, 2019 06:57 AM

    The best part is that I can not choose others. I copied the wireless profile and edited in the same way as ArubaOS Switching.

    cppm3.PNG

    Below is an error when selecting a new profile.

    cppm2.PNG