Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

802.1X Authentication Timeout - 12 hour intervals

This thread has been viewed 1 times
  • 1.  802.1X Authentication Timeout - 12 hour intervals

    Posted Apr 01, 2013 09:46 AM

    I wanted to post this out here to see if there are any suggestions/comments on this issue.

     

    We recently upgraded our RADIUS infrastructure to Cisco ACS. During this upgrade we moved our 802.1X authentication over to this new system. Since then, we've been having timeouts every 12 hours for users in which are authenticated - active and non-active sessions. The RADIUS logs indicate "empty TLS messages" which indicate to me a problem with either the supplicant or the RADIUS ACS. To troubleshoot, we removed the load balancer out of the equation and also pointed to a single RADIUS server instead of the cluster. I've checked settings on the Aruba side - which are set 24 hours, but since the controller is responsible for just passing the credentials through -- I'm not sure there is much more I can check/fine tune.

     

    Has anyone deployed the Cisco ACS and had similar issues? We do use certificates on a CAC card to make things more interesting.



  • 2.  RE: 802.1X Authentication Timeout - 12 hour intervals

    Posted Apr 01, 2013 10:08 AM

     

    You should probably look at the certificate setup.



  • 3.  RE: 802.1X Authentication Timeout - 12 hour intervals

    Posted Apr 01, 2013 12:33 PM

    Are you suggesting that something change on the PKI infrastructure?



  • 4.  RE: 802.1X Authentication Timeout - 12 hour intervals

    EMPLOYEE
    Posted Apr 01, 2013 12:39 PM

    Ask Cisco what the Empty TLS message means?



  • 5.  RE: 802.1X Authentication Timeout - 12 hour intervals

    Posted Apr 01, 2013 12:49 PM
    I have seen these type error message and it is related to the you way you have installed the cert on ACS server it's been a while that I worked with ACS so I don't remember all the steps but like Colin said try looking up what that error message means