Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

replacing controller breaks authentication

This thread has been viewed 0 times
  • 1.  replacing controller breaks authentication

    Posted Mar 21, 2014 09:41 AM

    Hi,

     

    setup : controller 650 authenticates using Clearpass 6.3.0.60537.  Everything works perfectly.

     

    Now :

     

    1. backup config

    2. get a new controller 650

    3. restore config

    4. bring controller up (same settings as previous controller thus)

     

    Now authentication fails (we get web authentication fails after using the guest portal).  Is there something cached or saved in Clearpass regarding the controller device (something based on the mac address)?  Only thing i haven't tried is rebooting Clearpass or removing/adding the controller device back in Clearpass.

     

    5. activate original controller back -> authentication works again...



  • 2.  RE: replacing controller breaks authentication

    EMPLOYEE
    Posted Mar 21, 2014 10:04 AM

    pnobels,

     

    I would look at Monitoring> Event Viewer in ClearPass to see if CPPM is not getting radius traffic from the ip address that it expects.



  • 3.  RE: replacing controller breaks authentication

    Posted Apr 02, 2014 03:22 AM
    can't see anything unusaul in there. I can see the request coming in
    access tracker, with the expected ip...

    --

    Kind regards,

    Peter Nobels

    *Peter Nobels* | System Engineer Business Information Systems & Solutions
    (BISS)
    T +32 3 250 56 41 | M +32 470 89 26 54 | nobels.peter@deme.be
    *DEME nv | Dredging, Environmental & Marine Engineering*


  • 4.  RE: replacing controller breaks authentication

    EMPLOYEE
    Posted Apr 02, 2014 03:22 AM
    Nothing is cached. It's all based on the Nas ip, name or SSID

    Double check your password on the radius settings on the controller.

    Look in the event viewer of CPPM to see if there are any errors.


  • 5.  RE: replacing controller breaks authentication

    EMPLOYEE
    Posted Apr 02, 2014 03:22 AM
    Are you using the same IP addresses on the new controller?






    Sent from Windows Mail


  • 6.  RE: replacing controller breaks authentication

    Posted Apr 02, 2014 04:17 AM
    No, other IP. Haven't been able to perform any further testing. My
    collegue had to return the controller.

    --

    Kind regards,

    Peter Nobels

    *Peter Nobels* | System Engineer Business Information Systems & Solutions
    (BISS)
    T +32 3 250 56 41 | M +32 470 89 26 54 | nobels.peter@deme.be
    *DEME nv | Dredging, Environmental & Marine Engineering*


  • 7.  RE: replacing controller breaks authentication

    EMPLOYEE
    Posted Apr 02, 2014 04:49 AM

    Problem solved :)