Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

7005 controller firewall issues

This thread has been viewed 0 times
  • 1.  7005 controller firewall issues

    Posted Jul 03, 2019 04:57 AM

    Here's an odd thing we've seen a couple of times...  When creating a new role the ACLs sometimes don't work properly. Only seen this on our lab environment, which is a clustered pair of 7005 controllers runing 8.5, with a virtual mobility master.

     

    First time this happened the implicit deny at the end of the ACLs just didn't work. More recently my colleague was testing config for a new role and some of the rules didn't work. After spending a long time trying to figure out what was wrong, removed all the ACLs, re-added them and it all works.

     

    I can't recreate this reliably, so there's no point raising a TAC call about it, but thought I'd put it out there in case anyone else has seen similar weirdness.



  • 2.  RE: 7005 controller firewall issues

    EMPLOYEE
    Posted Jul 03, 2019 07:15 AM

    You should double-check that the ACLs have been applied properly by using the "show rights" command against the role on the MD and "show acl hits".  Beyond that, there is not enough information in your post to determine what is wrong.



  • 3.  RE: 7005 controller firewall issues

    EMPLOYEE
    Posted Jul 04, 2019 05:45 AM

    one possible thing you may be hitting here is that existing flows in the session table (show datapath session) do not get reclassified against changes/additions to the acls. 

     

    For example, if I have an acl that says

     

    user any svc-ftp permit
    user any any deny

    Then say I open a ftp session on the client to some server, and while I am using the FTP session I removed the ACL for svc-ftp, the session would still continue without being denied.


    Maybe you encountered a variant of this ?

     



  • 4.  RE: 7005 controller firewall issues

    Posted Jul 11, 2019 03:40 AM

    That's a distinct possibility. Will definitely look out for this next time.

     

    Thanks.