Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

MAC Re-Auth every 1 second

This thread has been viewed 2 times
  • 1.  MAC Re-Auth every 1 second

    Posted Nov 22, 2018 07:10 AM

    I have Aruba switch with mac-auth configured for Mitel phones, but hey are re-authing every 1 second which seems excessive,

     

    I have found a setting for the reauth-period but i haven't set this.

     

    I can't find any documentation on reauthentication either. 



  • 2.  RE: MAC Re-Auth every 1 second

    EMPLOYEE
    Posted Nov 22, 2018 10:05 AM

    Not sure, if it similar issue but I have come across issue where Ip phones keep trying authentication and in CPPM we are seeing continous timeouts in access tracker.

    Issue got fixed after increasing the settings

    On the switch,changed the following port settings:

     

       aaa port-access authenticator

       aaa port-access authenticator quiet-period 30

       aaa port-access authenticator tx-period 10

       aaa port-access authenticator max-requests 3

       aaa port-access authenticator logoff-period 862400

       aaa port-access authenticator client-limit 3

     

    to:

     

    aaa port-access authenticator 1/11 quiet-period 60        à default value

    aaa port-access authenticator 1/11 tx-period 30             -> default value

    aaa port-access authenticator 1/11 max-requests 2       -> default value

    aaa port-access authenticator 1/11 client-limit 32

     

    After the restarts, all IP Phones are connected and authenticated using EAP-TLS. No timeouts occurred since.



  • 3.  RE: MAC Re-Auth every 1 second
    Best Answer

    Posted Nov 22, 2018 12:24 PM

    Figured it out, 

     

    turns out the phone had a switch plugged into the PC port and the devices where authenticating because they where accessing the network.

     

    I add the command 

     

    aaa port-access mac-based <port ID> addr-limit 10 

     

    the devices are not yet enabled for 802.1x