Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Terminating the session with ClearPass Hotspot

This thread has been viewed 2 times
  • 1.  Terminating the session with ClearPass Hotspot

    Posted Jun 02, 2014 02:07 PM

    Hi Airheads,

     

    I'm creating a Hotspot page with the self register service in ClearPass 6.3. I added the login page to the Captive portal profile in the controller. The redirecting process works fine and the login page appears when i associate with the Open SSID. I select to create a new account user, then i select the Hotspot plan, then i register in the form and finally it shows the user receipt. When i click the "start browsing button" i'm redirected to the login page instead gain access to the network. I can use the credentials generated by the hotspot to gain access but it don't lost the access (terminating the session) when the access time comes to end.

     

    Thanks in advance.



  • 2.  RE: Terminating the session with ClearPass Hotspot

    EMPLOYEE
    Posted Jun 02, 2014 02:46 PM


  • 3.  RE: Terminating the session with ClearPass Hotspot

    Posted Jun 02, 2014 03:09 PM

    Thanks but it is another issue. I try to terminate session when i access the network with the credentials generated with the Hotspot and it works but does not disconnect me after the purchased access time. 



  • 4.  RE: Terminating the session with ClearPass Hotspot

    EMPLOYEE
    Posted Jun 03, 2014 12:34 AM

    Couple of things

     

    1. Make sure COA is working correctly. This is usually the issue.....

    (A quick way to test is to open a device in access tracker and click Change Status)

     

    Screen Shot 2014-06-02 at 11.28.14 PM.png

     

    2. Are there anything showing in the event viewer in either CPPM or CPGuest?

     

    3. Make sure insight is enabled.

     

    4. What does your services look like?

     

    4. 



  • 5.  RE: Terminating the session with ClearPass Hotspot

    Posted Jun 03, 2014 02:14 PM

    Hi Troy,

     

    I check every bullet that you comment me:

     

    1. I understand that my CoA doesn't work correctly because shows an alert when i try to change the status in the Access Tracker: "Administratively-Prohibited", and in the active sessions it shows an alert similar "Error disconnecting session for user".

     

     CPPM.jpg

     

    Error ClearPass.jpg

     

    2.  In event viewer i can see only updates:

     

    Event.jpg

     

    3. Yes, Insight is enabled.

     

    4. This is the services that i'm testing:

     

    Services.jpg

     

    The 4th service is for the Hotspot self register captive portal and this is the summary:

     

    Service.jpg

     

    I need to configure something aditional to solve the CoA issues? or how can i configure de CoA correctly? 

     

    Thanks in advance.

     



  • 6.  RE: Terminating the session with ClearPass Hotspot

    Posted Jun 03, 2014 02:37 PM

    is CoA configured / allowed on the device where you try to stop the session? it has to be configured on both sides.



  • 7.  RE: Terminating the session with ClearPass Hotspot

    Posted Jun 03, 2014 03:08 PM

    I'm using an Aruba controller with 6.3.1.7 AOS but i don't know how to configurate the CoA for the RADIUS. Can you explain me how can i do it please?



  • 8.  RE: Terminating the session with ClearPass Hotspot

    Posted Jun 03, 2014 03:24 PM

    a little google goes a long way :)

     

    you configure CoA on the controller side via: security > authentication > servers > RFC 3576, add the IP of clearpass and the shared secret you also configured for radius.



  • 9.  RE: Terminating the session with ClearPass Hotspot

    Posted Jun 03, 2014 03:31 PM

    Thanks, but i've already added the ClearPass here and does not work the CoA generated in ClearPass:

     

    RFC.jpg



  • 10.  RE: Terminating the session with ClearPass Hotspot

    Posted Jun 03, 2014 03:33 PM

    are you sure the shared secrets match?

     

    is communication between clearpass and controller fully allowed? no firewall possibly blocking CoA traffic?

     

    under devices in clearpass, for your controller did you enable CoA?



  • 11.  RE: Terminating the session with ClearPass Hotspot

    Posted Jun 03, 2014 05:27 PM

    Yes, the shared secret match. I checked a couple of times and i check again with encrypt disable through the CLI. There's no firewall between controller and ClearPass. And yes, the device has the CoA checkbox enabled. Thanks.



  • 12.  RE: Terminating the session with ClearPass Hotspot

    EMPLOYEE
    Posted Jun 04, 2014 12:38 AM

    You need to make sure COA is enabled in 3 sections.

     

    1. CPPM

     

    Screen Shot 2014-06-03 at 11.30.40 PM.png

     

     

    2.  Controller "advance services>all profile Management>Wireless Lan>RFC3576

     

    Screen Shot 2014-06-03 at 11.27.54 PM.png

     

     

     

    3. Controller: Security > Authentication > Profiles your profile that is assigned to the user.

     

    Screen Shot 2014-06-03 at 11.28.57 PM.png