Security

last person joined: 11 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Wired 802.1x timeout issue

This thread has been viewed 19 times
  • 1.  Clearpass Wired 802.1x timeout issue

    Posted May 15, 2019 02:06 PM

    Hi everyone,


    I have run into a little bit of an issue with wired 802.1X on windows devices. I didn't see this in testing, but once everything was deployed to my production environment I am seeing around 10-15 windows clients a day timing out while they are booting or coming out of sleep. These clients timeout 2 times in a row, get sent a failed authentication message, and then fall back to MAC auth (sent to a guest zone). This can normally be sorted by disabling the nic and renabling it, but is a bit of a hassle and can be confusing to the customer.

    The Windows 802.1X settings are deployed through a group policy, and I'm wondering if it’s one of those settings that is causing the issue. We are using default settings, since they were working fine in the lab, but now I'm questioning if that is part of the problem.

     

     

    8021x settings.PNG

     

    Below is an example of what happens. Two timeouts and then it will fail back to MAC auth.  Sometimes the device corrects itself and will reauthenticate 20-30 minutes later, and sometimes it won't reauthenticate with 802.1x for hours.

    image.png

     

    I would be greatful for any tips.

     

    Thank you,

    Bobberson



  • 2.  RE: Clearpass Wired 802.1x timeout issue

    Posted May 15, 2019 05:15 PM
    In most cases this is a client device issue. Which OS are they running? During boot, are they first try to do a PXE boot?


  • 3.  RE: Clearpass Wired 802.1x timeout issue

    Posted May 15, 2019 05:26 PM

    It doesn't appear that PXE boot is occuring, and it shouldn't be in the boot order.  As far as OS, they are a mix of windows 7 and 10, but most of the issues seem to occur with the windows 7 devices.



  • 4.  RE: Clearpass Wired 802.1x timeout issue

    Posted May 15, 2019 05:50 PM
    Yes, I seen that problem also. Sometimes the EAP stack starts to late.
    Can you make a port mirror to see what happens with the EAP traffic? Also check the EAP logs at the client


  • 5.  RE: Clearpass Wired 802.1x timeout issue

    Posted Feb 23, 2020 10:37 AM

    I'm facing the same issue with Lenovo T490s.

    Have you found the solution for this behavior?

     

    Gadi



  • 6.  RE: Clearpass Wired 802.1x timeout issue

    Posted Sep 21, 2020 05:19 AM

    I seem to have the same issue. Has anybody found something to solve this?

     

    Regards,

    Lucas



  • 7.  RE: Clearpass Wired 802.1x timeout issue

    EMPLOYEE
    Posted Sep 21, 2020 08:41 AM

    Please be specific about your issue and open a new thread.  This one is old.