Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

guests users keep getting disconnected because of: Inactive | - Even when using mac cache

This thread has been viewed 0 times
  • 1.  guests users keep getting disconnected because of: Inactive | - Even when using mac cache

    Posted Jun 13, 2013 06:45 AM

    2.PNG3.PNGHi Guys,

    I have configured some guest portal with mac caching but..once in a while i can see devices getting inactive..

     

    How can i disable the inactive?

    why it's happning?

     



  • 2.  RE: guests users keep getting disconnected because of: Inactive | - Even when using mac cache

    EMPLOYEE
    Posted Jun 13, 2013 08:19 AM

    Do you also have mac authentication setup for that client?  Do you see the mac authentication happening?

     



  • 3.  RE: guests users keep getting disconnected because of: Inactive | - Even when using mac cache

    Posted Jun 13, 2013 08:45 AM

    mmm... i thought that the CPPM is saving all the guests MAC id's in order for them not need to re-login.

    But if also MAC auth on the AAA profile on the controller needed for that - i will configure it. Thanks on the info.



  • 4.  RE: guests users keep getting disconnected because of: Inactive | - Even when using mac cache

    EMPLOYEE
    Posted Jun 13, 2013 08:49 AM

    For Captive Portal and Mac Caching with CPPM, this is how it works:

     

    Guest Authenticates successfully via the captive portal

    CPPM creates a device entry with the corresponding mac address that expires at the same times as the guest account.

    Guest device goes to sleep or becomes idle and is removed from the user table

    Guest device wakes up and on that same Virtual AP, we have mac authentication configured to send the mac address of the guest to cppm over radius

    If mac authentication fails, guest ends up at the Captive Portal Screen

    If mac authentication passes, we give the guest the guest role silently and it is all good until that device entry expires

     

    If you have CPPm 6.1, use the service template to create your guest WLAN so that most of the configuration is done for you.

    On the controller side, you need to configure mac authentication in the AAA profile of that Virtual AP so that guests always send their mac address to CPPM over radius.



  • 5.  RE: guests users keep getting disconnected because of: Inactive | - Even when using mac cache

    Posted Jun 13, 2013 09:03 AM

    Thanks on the info

    I will test it - and let u know.

     

    I'am using ClearPass Policy Manager 6.0.2.46902 on CP-SW-VA platform