Security

last person joined: 8 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass didn't triggered CoA after GuestUser expiry

This thread has been viewed 13 times
  • 1.  Clearpass didn't triggered CoA after GuestUser expiry

    Posted Nov 01, 2018 09:41 AM

    need help!!

     

    Setup : Clearpass + Cisco 2960 switch. Captive portal based authentication for LAN users connected to cisco switch.

     

    Problem : After guest user got expired, clearpass is not triggering CoA action (when checked in access tracker tab, there is no CoA). But, when manually triggering CoA(Cisco Terminate session), CoA is working and client getting disconnected.

     

    More details : Using Wired Enforcement Policy document, I created service with 'Allow all mac auth' + 'web auth' for guest based solution for LAN users. user allowed initially with mac auth and given redirect url followed by web auth service to validate guest credentials and update Endpoint with username and role. Detailed screenshots attached.

     

    checklist :

    • Insight, accounting interm packets -> enabled
    • radius CoA enabled in device page
    • Expire post login, do expire policies added
    • Authorization in service -> all databases added
    • Guest>configuration>authentication settings>Selected NAS type as "Cisco systems(RFC 3576)"

     

    Please suggest any Tips:)

     

    Access Tracker logs one user

    ac1.JPGac 2.JPGac3.JPGac4.JPGac5.JPGac6.JPGac7.JPGac8.JPG

     

    Thanks

    Sairam

     

     

     

     



  • 2.  RE: Clearpass didn't triggered CoA after GuestUser expiry

    EMPLOYEE
    Posted Nov 01, 2018 09:45 AM
    Do you have Insight enabled in the cluster?


  • 3.  RE: Clearpass didn't triggered CoA after GuestUser expiry

    Posted Nov 01, 2018 01:16 PM
    Yes @cappalli. any other tips to try?


  • 4.  RE: Clearpass didn't triggered CoA after GuestUser expiry

    EMPLOYEE
    Posted Nov 01, 2018 01:19 PM
    Best to work with Aruba TAC.


  • 5.  RE: Clearpass didn't triggered CoA after GuestUser expiry
    Best Answer

    Posted Nov 01, 2018 07:27 PM

    Is a CoA needed for this?

    As far as I remember, ClearPass will set the dot1x session timeout to match the remaining time until guest expiration. I remember seeing that under the SQL query for the guest user source.

    The NAD would then force a reauth after expiration, without any CoA.

    But for that to work, Catalyst must be set to use the AAA server provided session timeout, that I think is not the default setting.



  • 6.  RE: Clearpass didn't triggered CoA after GuestUser expiry

    Posted Jan 03, 2019 02:41 PM

    Hi, i have the same problem with no coa after user account expiration. Using dot1x timeout is fine, but sometimes i need to change expiration of account while user is logged in (shorten time of expiration). How can i logout user from switch when shortened expiration time is reached?

     

    When i choose expiration time to "now" then it works ok - clearpass send coa, and user is redirected back to captive portal. Also when i logout user from active session then reautenthication occurs.



  • 7.  RE: Clearpass didn't triggered CoA after GuestUser expiry

    Posted Jan 04, 2019 12:32 AM

    PiotrC,

     

    Create a new endpoint update enforcement and use 'Expire-Time -Update' attribute.

     

    Capture.JPG



  • 8.  RE: Clearpass didn't triggered CoA after GuestUser expiry

    Posted Jan 04, 2019 02:40 AM

    I have configured that profile:

    enforcement-profile_expire-update.png

     

    But how to trigger that? Will it be tirggered automatically after changing of account expiration? Now i use this profile in mac auth enforcement policy:enforcement_policy.png

    Now i have tried to create guest account with expiration time set to 5 minutes after creating account. After user login the endpoint was updated with correct expiry time, but after expiration of account there is no action - user is still connected to network.



  • 9.  RE: Clearpass didn't triggered CoA after GuestUser expiry

    EMPLOYEE
    Posted Jan 04, 2019 07:24 AM

    Does Radius CoA is enabled in CPPM and also CPPM server is added as RFC server in controller?

    communitry.PNG



  • 10.  RE: Clearpass didn't triggered CoA after GuestUser expiry

    Posted Jan 04, 2019 07:27 AM

    Yes. When i change guest expiration to "Now" then clearpass send CoA to switch and switch reauthenticate user. So CoA is working fine.