Security

last person joined: 20 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

IOS Devices Reconnect Problem

This thread has been viewed 3 times
  • 1.  IOS Devices Reconnect Problem

    Posted May 13, 2013 01:51 PM
      |   view attached

    IOS devices cannot automatically reconnect after onboarding. I have COA and Switch IP setting enabled but after the 10 second waiting period it comes back failed to reconnect. Does anyone know what other configurations may cause the auto reconnect to fail?



  • 2.  RE: IOS Devices Reconnect Problem

    EMPLOYEE
    Posted May 13, 2013 09:41 PM

    Are you trying to reconnect to the same SSID or are you provisioning on one SSID and trying to have CPPM bounce the device to a different SSID?

     

    IOS devices have an issue where they will always reconnect to the last SSID they were connected to when they are bounced with a COA. Unfortunately it is a IOS issue and that is why you have the option if you use a separate SSID for onboarding that you have the auto or manual reconnect option disabled and post a message for the user to connect to the secure SSID. 

     

    iosreconnect.png



  • 3.  RE: IOS Devices Reconnect Problem

    Posted May 13, 2013 09:51 PM

    I am trying to have the IOS device disconnect and reconnect to the same SSID after onboarding. Right now a client has to enter airplane mode or disconnect from the SSID and then reconnect in order to gain access to the network. 



  • 4.  RE: IOS Devices Reconnect Problem

    EMPLOYEE
    Posted May 13, 2013 09:54 PM

    what wireless vendor are you using?



  • 5.  RE: IOS Devices Reconnect Problem

    Posted May 13, 2013 09:55 PM

    Aruba



  • 6.  RE: IOS Devices Reconnect Problem

    Posted May 13, 2013 09:56 PM

    Aruba Controller with CPPM 6.1



  • 7.  RE: IOS Devices Reconnect Problem

    EMPLOYEE
    Posted May 13, 2013 10:08 PM

    A couple of things to check

     

    1. Make sure you have COA enable on the device setting on the CPPM side.
    2. Make sure you have in the controller under Security > Authentication > L3 Authentication  that you check mark Add switch IP address in the redirection URL

    addswitch.png

    1. You add CPPM as a RFC 3576 in your AAA profile in the controller

    rfc.png

     

    1. And lastly in the CPGuest side go to Home » Administration » Plugin Manager under onboarding enable debugging (make sure you turn it off when you are done) and then look that the application log in the same section under administration.

     applicationlog.png



  • 8.  RE: IOS Devices Reconnect Problem

    Posted May 14, 2013 07:34 AM

    I have checked over the possible solutions that you have provided and they were all configured. However, while looking at the logs they prompt this as the reason for failure

    "Script:   /guest/mdps_profile.php
    Function: NwaMdpsProfileDoDisconnect
    Arguments:
    Details:  array (
      'result' => array (
        'error' => 1,
        'message' => 'Internal error while retrieving Insight server details. Please enable Insight on a server and continue.',
      ),
    )"

     



  • 9.  RE: IOS Devices Reconnect Problem

    Posted May 14, 2013 07:49 AM

    After enabling insight, this is the new error

     

    Script:   /guest/mdps_profile.php
    Function: NwaMdpsProfileDoDisconnect
    Arguments:
    Details:  array (
      'result' => array (
        'error' => 1,
        'message' => '{"content": {"cnc_actions": [{"status_message": "Radius [Aruba Terminate Session] failed for client FF:FF:FF:FF:FF:FF", "id": 1}]}, "id": "FF:FF:FF:FF:FF:FF_sess", "name": "cnc_response"}',
      ),
    )

    Mac address has been replaced.



  • 10.  RE: IOS Devices Reconnect Problem

    Posted May 14, 2013 01:22 PM

    This is the current config that is present on the CPPM and controller.

     

    I have COA, L3 Swith Ip, Insight, RFC 3576 server, and Automatic reconnet all enabled. However, this is what my IOS device is doing.

    Does anyone have suggestions.

     

    Attempt.PNG

    Application Log.PNGimage.png



  • 11.  RE: IOS Devices Reconnect Problem

    Posted May 15, 2013 10:37 AM

    Seems like the CoA messages are not working.  Is this a master or local controller? If it is a local, you may need to change the NAS IP to match the controller's IP address.  See this post:  

     

    http://community.arubanetworks.com/t5/ClearPass-formerly-known-as/CoA-Fails/td-p/60360

     

    Also, have a look at the RADIUS CoA stats on the controller:

     

    show aaa rfc-3576-server statistics

     



  • 12.  RE: IOS Devices Reconnect Problem

    Posted May 13, 2013 10:14 PM
    I have COA and the L3 redirection enabled, but I will check the AAA profile.