Security

last person joined: 14 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Guest Bandwidth Limitation is not working?

This thread has been viewed 5 times
  • 1.  Clearpass Guest Bandwidth Limitation is not working?

    Posted Dec 25, 2014 12:01 PM

    I have add guest access pre-auth service and add enforcemnt profile for Bandwidth limitaion but this is not working ?



  • 2.  RE: Clearpass Guest Bandwidth Limitation is not working?

    Posted Dec 25, 2014 12:37 PM
    Hi,

    Can you confirm accounting is working and can you post a copy of the post_auth config please?


  • 3.  RE: Clearpass Guest Bandwidth Limitation is not working?

    Posted Dec 25, 2014 01:34 PM
      |   view attached

    yes accounting is working, and profile as shown

     

     

     TypeName Value 
    1.Bandwidth-CheckAllowed-Limit=200
    2.Bandwidth-CheckLimit-Units=MB
    3.Bandwidth-CheckCheck-Type=Total
    4.Post-Auth-CheckAction=Disconnect
    5.Click to add...


  • 4.  RE: Clearpass Guest Bandwidth Limitation is not working?

    Posted Dec 26, 2014 04:46 PM

    The RADIUS interim accounting is received I think every 600 seconds (5mins) so we need to ensure that the 200MB in your example has been reached before we would trigger the enforcement profile for a user. Its possible that a user will have used their 200MB but we haven't received the interim updates.

     

    Can you follow a user/endpint session in the access-tracker please.... as the interim updates come it you will see on the accounting tab (confirm you have this as you said acc is working) the usage updating as we post the details we get from the interim acc updates to the access-tracker session for a user/endpoint. Lets get an absolute YES that the details are coming in and being added to a session as expected. 

     

    You said ACC was working, but lets check interim ACC is working.... ensure interim ACC is enabled in CPPM also please.

     



  • 5.  RE: Clearpass Guest Bandwidth Limitation is not working?

    Posted Dec 29, 2014 07:31 AM

    Yes, I saw the Radius response that contain the 200 MB in access tracker

     

    now I understood from you that I should wait 5 min before testing it?!

     

     

     

     



  • 6.  RE: Clearpass Guest Bandwidth Limitation is not working?

    Posted Dec 29, 2014 03:02 PM

    how exactly do you want to wait before testing it? it is something that happens more or less automatically.

     

    in general the updates from radius accounting don't happen realtime, there is an interval. so it is possible that just before the interval the 200 mb isn't reached, but x minutes later it is. so it might be the disconnect happens a little later then expected.

     

    if that is not working for you then you should really provide more info for the people here to check. you say everything is configured correctly but it doesnt work so there must be something wrong.