Security

last person joined: 23 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

MAC Authentication accepted but captive portal keeps popping up

This thread has been viewed 1 times
  • 1.  MAC Authentication accepted but captive portal keeps popping up

    Posted Jul 27, 2018 04:31 AM

    Hey

     

    I have a guest portal that works in every way with phone number as username and SMS as code on initial login. I have 6 months as Mac auth expiry.

     

    My problem is when MAC authentication is performed the next day when a user is trying to connect, it gets accept and the cppm user role is assigned, but the captive portal pops up on for example a Apple Iphone. 

     

    Can anyone help me out ?



  • 2.  RE: MAC Authentication accepted but captive portal keeps popping up

    Posted Jul 27, 2018 07:42 AM
    Did you use the Mac caching wizard in ClearPass to build your services/policies/profiles?



    Thank you

    Victor Fabian

    Pardon typos sent from Mobile


  • 3.  RE: MAC Authentication accepted but captive portal keeps popping up

    Posted Jul 27, 2018 07:48 AM

    Yes, I think it fails here:

     

    cppm-mac.JPG

    it should hit the first-applicable which is "[Allow Access Profile], [GUEST Guest Profile]", but it goes to the next enforcment profile "[Allow Access Profile], [GUEST Captive Portal Profile]". I just cannot understand why.



  • 4.  RE: MAC Authentication accepted but captive portal keeps popping up

    Posted Jul 27, 2018 08:28 AM

    Can you share the post-auth profile (Guest Mac Caching Profile) assigned under the mac caching service

     

    Also can you share the role mapping for the mac authentication service



  • 5.  RE: MAC Authentication accepted but captive portal keeps popping up

    Posted Aug 06, 2018 06:04 AM

    Sorry for late reply.

     

    Here are post-auth profile (Guest Mac Caching Profile):

     

    postauth1.JPG

    Here are role mapping for the mac authentication service:

     

    rolemap1.JPG



  • 6.  RE: MAC Authentication accepted but captive portal keeps popping up

    Posted Aug 06, 2018 06:26 AM

    I see this now:

     

    auth-attri1.JPG

    Are this value set by the orginal form: guest_register with the field: expire_afer ?



  • 7.  RE: MAC Authentication accepted but captive portal keeps popping up

    Posted Aug 07, 2018 06:15 AM

    When removing the following from the generated guest-mac-policy:

     

    AND(Authorization:[Guest User Repository]:AccountExpired EQUALS false)
    AND(Authorization:[Guest User Repository]:AccountEnabled EQUALS true)

     

    Then everything works as expected. Users who never have authenticated get captive portal, users with the mac-expiry-auth value set gets mac authentication.