Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

clearpass policy manager - network device issue

This thread has been viewed 2 times
  • 1.  clearpass policy manager - network device issue

    Posted May 04, 2015 06:48 AM

    Hello,

     

    I can not authenticate a client using CPM. The network access device is IAP-205. i can see only following information on event viewer.

     

    Source Radius

    Level WARN

    Category Authentication

    Action Unknow

    Decription: Ignoring request from unknow client ...

     

    I do not understand why the issue is occured.

     



  • 2.  RE: clearpass policy manager - network device issue

    EMPLOYEE
    Posted May 04, 2015 07:37 AM

    Mathew0306,

     

    Did you add the IAP's ip address as a radius client under Configuration> Network> Devices?

     

    The Event Viewer should say the ip address that the radius traffic is coming from.  In IAP, also you have the option of enabling "Dynamic Radius Proxy" where all of the radius traffic of an IAP cluster comes from the same ip address:  http://www.arubanetworks.com/techdocs/Instant_41_WebHelp/InstantWebHelp.htm#UG_files/Authentication/Dynamic Proxy RADIUS.htm

     



  • 3.  RE: clearpass policy manager - network device issue

    Posted May 04, 2015 08:02 AM

    HI,

     

    As per the information provided, the RADIUS client is not configured properly. the best solution is,configure VC IP address and enable "Dynamic RADIUS proxy" option from Advanced options of System menu.

     

    For your ref :

     

    DRP1.png

    Please feel free if the issue is not resolved.



  • 4.  RE: clearpass policy manager - network device issue

    Posted May 04, 2015 04:06 PM

    Hi,

     

    Your advice does not resolve me issue. I had configured the network device before I created this topic.

    In my network works only one IAP, so I assumed that setting the VC and Radius Proxy would not help m but I have done it. Unfortunatelly I can see the same warn message.

     

    Could anybody help me?

     

    Regards,

    Mateusz



  • 5.  RE: clearpass policy manager - network device issue

    EMPLOYEE
    Posted May 04, 2015 04:17 PM

    What ip address does the event viewer say the traffic is coming from?

    Set the VC address and dynamic radius proxy, so that you can narrow your issue.



  • 6.  RE: clearpass policy manager - network device issue

    EMPLOYEE
    Posted May 04, 2015 04:18 PM
    the event should show you the IP of the NAS that is trying to connect


  • 7.  RE: clearpass policy manager - network device issue

    Posted May 04, 2015 04:29 PM

    Hello,

     

    I have set the VC and Radius Proxy, but It does not resolve this issue.

     

    In the event viewer I can see exactly the same IP address which I configured as VC and in the Network -> Device tab.

     

    Regards,

    Mathew



  • 8.  RE: clearpass policy manager - network device issue

    EMPLOYEE
    Posted May 04, 2015 04:30 PM

    mathew0306,

     

    Please feel free to open a TAC case, then.