Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

config mobility controller and clearpass

This thread has been viewed 13 times
  • 1.  config mobility controller and clearpass

    Posted Nov 10, 2016 01:28 PM

    I'm trying to connect my Aruba MC 7210 to my ClearPass 6.6 appliance but I get radius error.

     

    1. In ClearPass - I Configured my MC 7210 "\Configuration\Network\Devices\"

     

    2. In MC 7210 - I configured my Radius Server(ClearPass)

    "\Configuration\authentication\Servers\Radius Server"

     

    3. In MC 7210 - I configured my Server Group

    "\Configuration\authentication\Servers\Server Group"

     

    4. In MC 7210 - I configured my RFC 3576 Server(ClearPass)

    "\Configuration\authentication\Servers\RFC 3576 Server"

     

    5. In MC 7210 - I configured my WLAN pointing to Radius Server

     

    And I receive Radius Server Authentication Error. What can I do?

     

    Here we have some logs...

    [Th 13 Req 5 SessId R00000005-01-5824b6c9] ERROR RadiusServer.Radius - rlm_service: Service Categorization failed

     

    [Th 13 Req 5 SessId R00000005-01-5824b6c9] ERROR RadiusServer.Radius - rlm_service: Policy Server result = 65535, msg = Service classification failed

     

    [RequestHandler-1-0x7f08245e2700 r=psauto-1478731079-11 h=223 r=R00000005-01-5824b6c9] ERROR Core.ServiceReqHandler - doServiceClassification: Error. Ret code=0 response list size=0



  • 2.  RE: config mobility controller and clearpass

    EMPLOYEE
    Posted Nov 10, 2016 01:34 PM
    Please post a screenshot of your service.


  • 3.  RE: config mobility controller and clearpass

    Posted Nov 10, 2016 01:41 PM
      |   view attached

    Service.PNG



  • 4.  RE: config mobility controller and clearpass
    Best Answer

    EMPLOYEE
    Posted Nov 10, 2016 01:53 PM
    OK. Look through the input tab in the access tracker request and make sure
    those all match. Also, remove rule 3.


  • 5.  RE: config mobility controller and clearpass

    Posted Nov 10, 2016 02:04 PM

    Hi, All this information is correct, I removed rule 3 and is the same

     

    Input.PNG



  • 6.  RE: config mobility controller and clearpass
    Best Answer

    EMPLOYEE
    Posted Nov 10, 2016 02:08 PM
    Your SSID rule is likely the issue. You're searching for "secure", but the
    SSID is "DigiWorld.Aruba"


  • 7.  RE: config mobility controller and clearpass

    Posted Nov 10, 2016 02:15 PM

    Thanks a lot, I solved it and now I get this

     

    ERROR RadiusServer.Radius - rlm_peap: Configured for public mode, but request username hrojas does not match public username public, rejecting

     

    How can I config the Authentication without public mode?

     

     



  • 8.  RE: config mobility controller and clearpass

    EMPLOYEE
    Posted Nov 10, 2016 02:17 PM
    If you're not using EAP-PEAP-Public, remove EAP-PEAP-Public from the
    authentication methods list and add EAP-PEAP.


  • 9.  RE: config mobility controller and clearpass

    Posted Nov 10, 2016 02:19 PM

    Yes, but I dont't have that choise. Can't I use EAP-MSChap2?



  • 10.  RE: config mobility controller and clearpass

    EMPLOYEE
    Posted Nov 10, 2016 02:22 PM
    Are you using a RADIUS service? You should definitely have an [EAP PEAP]
    option in the list. Please provide a screenshot.


  • 11.  RE: config mobility controller and clearpass

    Posted Nov 10, 2016 02:31 PM

    Auth.png



  • 12.  RE: config mobility controller and clearpass
    Best Answer

    EMPLOYEE
    Posted Nov 10, 2016 02:37 PM
    You have high capacity guest mode enabled. You can only use EAP-PEAP Public
    in this mode.


  • 13.  RE: config mobility controller and clearpass

    Posted Nov 10, 2016 02:44 PM

    Yes and how can I use anthore methods?



  • 14.  RE: config mobility controller and clearpass

    EMPLOYEE
    Posted Nov 10, 2016 02:49 PM
    You cannot use other EAP methods in HCG mode. It is designed for scaling in
    large guest deployments.


  • 15.  RE: config mobility controller and clearpass

    Posted Nov 10, 2016 03:00 PM

    Thanks a lot, now I can surf using my WLAN and ClearPass

     

    This solutions is oriented to a hotel and good for me to use HCG mode.

    Can I use another methods for authentication??



  • 16.  RE: config mobility controller and clearpass

    Posted Nov 10, 2016 02:08 PM

    Hi, All this information is correct, I removed rule 3 and is the same.

    Logs:

    ERROR RadiusServer.Radius - rlm_service: Service Categorization failed

     

    ERROR Core.ServiceReqHandler - doServiceClassification: Error. Ret code=0 response list size=0

     

    ERROR RadiusServer.Radius - rlm_service: Policy Server result = 65535, msg = Service classification failed

    Input.PNG