Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Endpoint losing network access

This thread has been viewed 0 times
  • 1.  Endpoint losing network access

    Posted Mar 01, 2020 09:11 AM

    Hello,

     

    I am setting up ClearPass in test environment. I am using AD based   authentication (username-password). I have created a wired 802.1x service. The service is in monitor mode but as soon as I enable 802.1x on the switch, the clients loose network access.

     

    I mean the users are already authenticated against AD and had network access before 802.1x was enabled. Why does it lose access when 802.1x is enabled on the switch? 

     

    Am I missing something? Should the enpoints be restarted after enabling 802.1x on the switch in order for them to reauthenticate?



  • 2.  RE: Endpoint losing network access

    Posted Mar 01, 2020 11:59 AM

    Hi, 

     

    What do you see in access tracker?



  • 3.  RE: Endpoint losing network access

    Posted Mar 02, 2020 07:46 AM

    I see access reject messages.



  • 4.  RE: Endpoint losing network access

    Posted Mar 02, 2020 07:48 AM

    Hi, 

     

    Please share snapshot of your role mapping and enforcement policies



  • 5.  RE: Endpoint losing network access

    Posted Mar 02, 2020 07:50 AM

    Hello Ronin,

     

    Thanks for your reply. I do not have access to the UI as of now. I will be sending it when I have the access.

    In general should monitor mode affect network access simply because 802.1x is enabled on the switchport?



  • 6.  RE: Endpoint losing network access

    Posted Mar 02, 2020 07:54 AM
    No it shouldnt. Its usually recommended to start with monitor mode if you
    are unclear of what effects it might have on the network.

    In your case it is indeed going against desired result


  • 7.  RE: Endpoint losing network access

    Posted Mar 02, 2020 07:56 AM

    Also please share the make/model of switch and configuration you are doing on it



  • 8.  RE: Endpoint losing network access

    Posted Mar 02, 2020 07:58 AM

    Sure Ronin. I will be back with the required details. Thanks



  • 9.  RE: Endpoint losing network access

    Posted Mar 02, 2020 08:05 AM

    In addition to the role mapping and enforcement, in access tracker under the reject messages you are getting, is there an alerts tab? If there is, what alerts are there?