Security

last person joined: 20 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

no authentication source in service

This thread has been viewed 12 times
  • 1.  no authentication source in service

    Posted May 15, 2014 05:27 AM

    Hello Everyone,

     

    I have a service in my CPPM for mac based VLAN allocation. It is accepting requests from users connected to a specific switch and telling them which vlan they are depending on some attributes like 'OS Family', etc.

     

    This was working perfectly a few weeks ago, but not anymore since I am trying to re-do some tests this morning. I installed the cumulative patch 2 yesterday.

     

    The difference I can see when I compare the requests which were working and the ones wich not in access tracker is the 'Authentication Source'. It is now 'None' and was 'Local:Localhost' before.

    Also, I don't have any authorization attributes anymore in the request despite the fact that the endpoint has been profiled.

     

    Hope you can help me.

     

    Thanks in advance,

     

    - nice2k



  • 2.  RE: no authentication source in service

    EMPLOYEE
    Posted May 15, 2014 05:33 AM

    You need to add an authentication source to your service.  The Endpoints repository?  You also might want to open up a case to determine why the patch changed things.



  • 3.  RE: no authentication source in service

    Posted May 15, 2014 05:35 AM
      |   view attached

    Hello,

     

    Thanks for your answer.

    I already have the Endpoints Repository as an Authentication source. I also tried to recreate the service without success...



  • 4.  RE: no authentication source in service

    EMPLOYEE
    Posted May 15, 2014 05:36 AM

    Does the Access tracker say that it is still being handled by the same service?



  • 5.  RE: no authentication source in service

    Posted May 15, 2014 05:40 AM

    Yes, here are some screen captures.

     

     

     



  • 6.  RE: no authentication source in service

    EMPLOYEE
    Posted May 15, 2014 05:42 AM

    It looks like it is sending back the VLAN 13 enforcement profile.  What is in that enforcement profile?

     



  • 7.  RE: no authentication source in service

    Posted May 15, 2014 05:48 AM
      |   view attached

    Yes, it is an enforcement profile just to put the user in the vlan 13. I have one for each vlan and this one is the default profile.

     

    My enforcement policy says : If this user is os OS Family, put it in the vlan 10.

    It is putting the user in the vlan 13 because it's the default enforcement profile (he can't find the OS Family attribute, I don't see the authorization attributes anymore in the computed attributes) 



  • 8.  RE: no authentication source in service

    EMPLOYEE
    Posted May 15, 2014 05:51 AM

    Well,

     

    Does an OS family exist for that endpoint in the Endpoints repository?  If the device does not exist or it does not have an OS family, that attribute will not show up or be keyed on.  If it is a new device and it has never sent DHCP information to CPPM, it would not be aware of the OS family, because it does not have that information.



  • 9.  RE: no authentication source in service

    Posted May 15, 2014 05:52 AM
      |   view attached

    Yes, the device has been profiled and has the attribute OS Family...



  • 10.  RE: no authentication source in service

    EMPLOYEE
    Posted May 15, 2014 05:54 AM

    Please open up a support case.  That is all that you are supposed to do.

     



  • 11.  RE: no authentication source in service

    Posted May 15, 2014 05:55 AM

    Okay, thanks for your help.



  • 12.  RE: no authentication source in service
    Best Answer

    Posted May 16, 2014 10:53 AM

    Okay, I restored the configuration from a 1 week old backup and it worked.

     

    - nice2k



  • 13.  RE: no authentication source in service

    EMPLOYEE
    Posted May 16, 2014 10:53 AM

    Was it any different that you could tell?



  • 14.  RE: no authentication source in service

    Posted May 16, 2014 11:00 AM

    Don't think so... At least the service and Policy. The only thing I suspect to be different is the selection of the vendor indication on the 'Device' entry.

    I have a Cisco switch and I think it was on 'Aruba'. Not sure though.

     

    - nice2k



  • 15.  RE: no authentication source in service

    EMPLOYEE
    Posted May 16, 2014 11:00 AM

    Glad to hear it is solved.



  • 16.  RE: no authentication source in service

    Posted May 16, 2014 11:01 AM

    Me too ! It's working perfectly now :)