Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Supplemental Machine Authentication Failure

This thread has been viewed 0 times
  • 1.  Supplemental Machine Authentication Failure

    Posted Sep 23, 2015 08:30 AM

    Hello,

     

    When we implemented our Aruba Network back in 2012 we put in a RADIUS server and began doing 802.1x auth with all capable clients. Since day one, we had issues with domain-joined machines and Machine Authentication. We setup roles where if a device passes machine and user auth, they get full access to our LAN but if they fail machine auth, they are placed in a BYOD role. Various laptops would start out in the full access role but randomly (while in use) move to the BYOD role causing users applications to freeze. We tried everything and eventually settled on issue with the chipsets in the laptops being the issue and turned off machine authentication.

     

    Now, after removing all these devices and replacing them with new ones, upon turning machine authentication back on we are having the same issue. Has anyone run into a similar situation and how was it resolved?

     

    Thanks,

     

    Daniel



  • 2.  RE: Supplemental Machine Authentication Failure

    EMPLOYEE
    Posted Sep 23, 2015 08:37 AM

    Which radius server is this?  What rules are you using on the radius server and what attributes are you sending back to differentiate between BYOD and machine authenticated?

     



  • 3.  RE: Supplemental Machine Authentication Failure

    EMPLOYEE
    Posted Sep 23, 2015 08:38 AM
    Try increasing the machine authentication cache time.


    Thanks, 
    Tim


  • 4.  RE: Supplemental Machine Authentication Failure

    Posted Sep 23, 2015 10:04 AM

    This is a Windows-based RADIUS server.

     

    I will try increase the machine authentication cache time and see if that makes a difference.

     

    Thanks,

    Daniel