Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass - wired MAC authentication

This thread has been viewed 20 times
  • 1.  Clearpass - wired MAC authentication

    Posted Jul 20, 2020 07:59 AM

    Hello,


    I have problem with MAC authentication. MAC authentication works fine when device is connected via Aruba switch, but not working on other manufacturer switch.

    I don’t know it is the case, but MAC authentication via Aruba switch in Clearpass RADIUS requests username always in lowercase (Radius:IETF:User-Name aabbccddeeff), but RADIUS requests from other switch - uppercase (Radius:IETF:User-Name AABBCCDDEEFF)..

     

    And I get this error:

    Error Code: 204

    Error Category: Authentication failure

    Error Message: Failed to classify request to service

    Alerts for this Request

    RADIUS Service Categorization failed

     

    MAC authentication service:

    Radius:IETF NAS-Port-Type BELONGS_TO Ethernet (15), Wireless-802.11 (19)

    Radius:IETF Service-Type BELONGS_TO Login-User (1), Call-Check (10)

    Connection Client-Mac-Address EQUALS %{Radius:IETF:User-Name}

     

     

    So it is the problem with MAC format and this is why service cannot be categorized? Or..? How can I solve this problem?



  • 2.  RE: Clearpass - wired MAC authentication

    Posted Jul 20, 2020 08:54 AM
    What vendor are you using ?

    Sent from Mail for Windows 10


  • 3.  RE: Clearpass - wired MAC authentication

    Posted Jul 20, 2020 10:23 AM

    Netgear



  • 4.  RE: Clearpass - wired MAC authentication

    MVP EXPERT
    Posted Jul 20, 2020 01:17 PM

    Look at the RADIUS request and see if the service rules match. If they don't, change them.



  • 5.  RE: Clearpass - wired MAC authentication
    Best Answer

    Posted Jul 21, 2020 09:08 AM

    SOLUTION..

    In Service Rules one of the condition did not match. If I remove: Radius:IETF Service-Type BELONGS_TO Login-User (1), Call-Check (10) then MAC authentication works via Netgear switch too..