Security

last person joined: 7 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Unable to see any log in NAP Server event viewer

This thread has been viewed 2 times
  • 1.  Unable to see any log in NAP Server event viewer

    Posted Sep 15, 2014 10:48 AM

    Hello,

     

    I've got an Aruba 650 appliance. We use a NAP server to validate user with RADIUS.

    User are connecting perfectly but when I go to see the event viewer any events are in NAP section. I have try also to test with "AAA Test Server", the tool work fine but no events are registered in the server.

     

    I am scared in case something fail and I have no option to see the logs.

     

    Regards,



  • 2.  RE: Unable to see any log in NAP Server event viewer

    EMPLOYEE
    Posted Sep 15, 2014 10:49 AM

    Are you looking under the Security logs?



  • 3.  RE: Unable to see any log in NAP Server event viewer

    Posted Sep 15, 2014 10:55 AM

    No, I am looking under Server Roles - Network Policy and Access Services.

     

    I always have looked there. Maybe the update we made on aruba controller was the guilty.

     

    Thanks,



  • 4.  RE: Unable to see any log in NAP Server event viewer

    EMPLOYEE
    Posted Sep 15, 2014 10:58 AM
    If 802.1X is working, then there's nothing on the controller that would prevent logging. Are you seeing anything under the NPS logs?


  • 5.  RE: Unable to see any log in NAP Server event viewer

    Posted Sep 16, 2014 02:22 AM

    I can see any log under NPS. No logs, I deleted to see if something new is added but nothing happens.

     

    I don't understand what you mean with "802.1X is working", do you mean that the user are login without problems?

     

     



  • 6.  RE: Unable to see any log in NAP Server event viewer
    Best Answer



  • 7.  RE: Unable to see any log in NAP Server event viewer

    Posted Sep 16, 2014 03:16 AM

    Thanks so much. It's solved.

     

    auditpol /set /subcategory:"Network Policy Server" /success:enable /failure:enable

    This command enable audit, but local policy overwrite it.

     

    I finally have change the local policy and it works !!!

    The success/failure setting can be found at Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> Audit Policies -> Logon/Logoff -> Audit Network Policy Server.

     

    Thanks again.