Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

RADIUS Timeout on some IAPs

This thread has been viewed 3 times
  • 1.  RADIUS Timeout on some IAPs

    Posted Apr 02, 2019 12:51 AM

    We are getting a high amount of RADIUS Timeouts, but not on all IAPs(?!)

     

    Authentication is through CLEARPASS

     

    Test device is a Surface running Windows 10

     

    When connecting to AP1 (which is a VC) - the authentication request in Airwave is ACCEPT

    Authentication Method: EAP-PEAP,EAP-MSCHAPv2

    Authentication Source: AD:dc1.our.domain.com

     

    When connecting to AP2 - autentication request in Airwave is TIMEOUT

    Authentication Method: EAP

    Authentication Source: None

     

    Error Code: 9002

    RADIUS Client did not complete EAP transaction

     

    APs are the same model - Aruba AP 325

    Firmware/image is the same

    VLANs on respective switches are the same

    Dynamic Proxy is enabled for RADIUS and TACACS

     

    Other posts regarding this error seem to indicate a certificate issue, however this connection works fine on one AP and not another - so I think we can safely assume the certificate is valid.

     

     



  • 2.  RE: RADIUS Timeout on some IAPs

    EMPLOYEE
    Posted Apr 02, 2019 03:37 AM

    With regards to the 9002, that often happens when you have recently changed the radius server certificate and a human is not there to click on "accept" to the new cert on some clients.  It might not be your situation, but it is one of the situations.



  • 3.  RE: RADIUS Timeout on some IAPs

    Posted Apr 09, 2019 10:09 PM

    Thanks for the response, but it doesn't appear to be the case in this instance.



  • 4.  RE: RADIUS Timeout on some IAPs

    EMPLOYEE
    Posted Apr 10, 2019 08:39 AM
    How many ClearPass servers are there in your environment? Just one, or are there others?


  • 5.  RE: RADIUS Timeout on some IAPs

    Posted Apr 10, 2019 06:43 PM

    We have one ClearPass server and domain controller (NPS) as the secondary authentication server.



  • 6.  RE: RADIUS Timeout on some IAPs

    EMPLOYEE
    Posted Apr 12, 2019 10:25 AM

    Is the same Radius certificate installed on both servers (ClearPass and NPS)?



  • 7.  RE: RADIUS Timeout on some IAPs

    Posted Apr 14, 2019 10:02 PM

    No the certificates are different



  • 8.  RE: RADIUS Timeout on some IAPs

    Posted Apr 15, 2019 03:34 AM
    Please make sure that the client is accepting both certificates.
    Preferably you should use the same authentication backend and certificates for your primary and secondary authentication server.

    Like already mentioned it looks like the client isn't accepting the server side certificate.


  • 9.  RE: RADIUS Timeout on some IAPs

    Posted Apr 15, 2019 07:08 PM

    The Root CA Certificate is the same on Airwave and the DC. The RADIUS/EAP Server Certificate was issued by our DC. 



  • 10.  RE: RADIUS Timeout on some IAPs

    Posted Mar 18, 2020 01:03 PM

    Did you ever find a solution for this?