Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Seeing 400 requests in access tracker in a span of a day for one device.

This thread has been viewed 1 times
  • 1.  Seeing 400 requests in access tracker in a span of a day for one device.

    Posted Feb 01, 2020 03:32 PM

    This has been happening since implementing clearpass, It happens with any type of device and it doens't matter if it mac auth or 802.1x. 

     

    Access tracker shows multple requests within seconds of each other. 

     

    This isn't a specific device or locatino issue it happens to all devices. 


    Why is this happening? In some cases my Wireless client is stationary and there is only one AP in the area and it is right above it. 

     

    Is there a setting on my Instant controller that is causing all these requests? I have IAP 315's and the newest version of Clearpass . 

     

    Thank you 



  • 2.  RE: Seeing 400 requests in access tracker in a span of a day for one device.

    Posted Feb 02, 2020 05:13 AM

    Did you enable radius proxy on the VC? It should be enabled.

     

    Did you enable some protocols that might be unsupported by the client? 802.11 r / k / v ? 

     

    Do you see errors in clearpass or the client?

     



  • 3.  RE: Seeing 400 requests in access tracker in a span of a day for one device.

    Posted Feb 03, 2020 01:54 PM
    I have Radius Dynamic Proxy enabled. This SSID is my guest network,
    although I see the same behavior from my Internal 802.1x clients as well.

    I am using my guest network to add wireless network devices via mac auth
    Regular expressions. Since I am already doing vouchers via sponsors then
    mac auth.

    If the device is authenticated via REGEX then it gets dropped onto my
    network on the internal vlan.

    I was just watching the access tracker and pinging the device continously,
    every time it reauthenticates I drop a couple pings.

    I have the reauth interval set default at 0 (which I thought meant to not
    reauthenticate)


  • 4.  RE: Seeing 400 requests in access tracker in a span of a day for one device.

    Posted Feb 02, 2020 05:25 AM
    Hello,

    Is that only about Auth request?
    Did CoA happen? What's in the accounting log?

    Could you post one or to requests?
    And maybe your instant config?

    Regards