Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Expired accounts can still access websites.

This thread has been viewed 1 times
  • 1.  Expired accounts can still access websites.

    Posted Jun 11, 2014 07:42 AM

    Greetings,

     

    I hope someone can help. 

     

    We have Clearpass guest v6.3.1.29787 and were testing the expiry feature.  The expiry type is set to disable and logout, however once the account does expire, the connected account is still able to access websites (not just previously visited / cached ones).

     

    The account on guest manager is shown as expired.

     

    Anyone come across this before?

     

    TIA

     

    Gordie 

     



  • 2.  RE: Expired accounts can still access websites.

    EMPLOYEE
    Posted Jun 11, 2014 07:44 AM
    Is it an Aruba wireless controller? Do you have RADIUS CoA and accounting enabled?


  • 3.  RE: Expired accounts can still access websites.

    Posted Jun 11, 2014 07:48 AM

    Hi Tim,

     

    Sorry, yes.  We have Aruba iAP 105 AP managed by Airwave.


    We do not have CoA or accounting turned on.  We are using the Clearpass appliance as a RADIUS server.

     

    TIA

     

    G



  • 4.  RE: Expired accounts can still access websites.

    EMPLOYEE
    Posted Jun 11, 2014 07:50 AM
    If you want the device to be disconnected immediately when the account expires, you need to turn both those features on in both Instant and CPG


  • 5.  RE: Expired accounts can still access websites.

    Posted Jun 11, 2014 08:11 AM

    Cheers Tim,

     

    I have checked this setting in CPG, but cant find it on the Instant.  Where about is this setting?

     

    TIA

     

    G



  • 6.  RE: Expired accounts can still access websites.
    Best Answer

    EMPLOYEE
    Posted Jun 11, 2014 08:39 AM

    CoA (RFC 3576) is found in your authentication server settings.

     

    instant-rfc3576.png

     

    Accounting is found under the SSIDs security settings.

     

    instant-accounting.png



  • 7.  RE: Expired accounts can still access websites.

    Posted Jun 11, 2014 08:55 AM

    Thanks Tim,  appreciate your help.

     

    I have made the changes, but its still not logging me off when my session expires.  It has had the side effect of adding data to active sessions :)

     

     



  • 8.  RE: Expired accounts can still access websites.

    Posted Jun 11, 2014 10:26 AM

    Did you start a new session with the client and delete the old one ?

     

    You may have to remove the client session from the Virtual Controller List and then try again.