Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass Communication Issue w/ Controller

This thread has been viewed 0 times
  • 1.  ClearPass Communication Issue w/ Controller

    MVP
    Posted May 26, 2017 11:55 AM

    Hi community,

     

    I'm trying to work on an existing CPPM and Controller setup, but having some authentication issues. I'm not seeing any requests in Access Tracker or in the Event Viewer logs for the controller sending a MAC Auth request for a client. It appears as if the traffic isn't reaching clearpass. I did a packet capture on CPPM to verify, and did get the request:

     

    2017-05-26-Image-002.png

    I see the initial request, and when I dive into the RADIUS portion, it has the MAC address as username. I then see an ICMP attempt, which fails. Then a retry from the controller and so on. 

     

    If I manually run a ping from CPPM (same interface) to the same controller, it is successful.

     

    2017-05-26-Image-003.png

     

    Whats the difference between the ICMP traffic during the RADIUS request and the ICMP traffic when doing a regular ping command? Why would one work and the other doesn't?



  • 2.  RE: ClearPass Communication Issue w/ Controller

    MVP
    Posted May 26, 2017 12:00 PM

    Also, logs on the controller show RADIUS server timeout, no response from server for the MAC auth.

     

    Controller is .240 and ClearPass is .127



  • 3.  RE: ClearPass Communication Issue w/ Controller

    Posted May 26, 2017 12:07 PM
    Are you using the Management and Data Port ?


  • 4.  RE: ClearPass Communication Issue w/ Controller

    MVP
    Posted May 26, 2017 12:22 PM

    We have both configured, but its all going through management.



  • 5.  RE: ClearPass Communication Issue w/ Controller

    Posted May 26, 2017 12:50 PM
    Is the data port trusted or DMZ ?


  • 6.  RE: ClearPass Communication Issue w/ Controller
    Best Answer

    MVP
    Posted May 26, 2017 09:16 PM

    We identified the problem - The RADIUS Server service in ClearPass had been stopped, for an unknown reason. This CPPM server is in a demo environment and had not been used for months. Not sure when it stopped, but that was the cause. We started it and got authentication requests immediately.

     

    Thanks for the help.



  • 7.  RE: ClearPass Communication Issue w/ Controller

    EMPLOYEE
    Posted May 26, 2017 09:21 PM

    When you upgrade the server certificate, you have to restart the radius server service manually...



  • 8.  RE: ClearPass Communication Issue w/ Controller

    MVP
    Posted May 26, 2017 09:23 PM

    That is interesting, that very well may have been what happened. I wasn't aware of that, thanks for the info!