Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

ArubaOS 6.1.3.1 User derivation rule not working

This thread has been viewed 1 times
  • 1.  ArubaOS 6.1.3.1 User derivation rule not working

    Posted Apr 19, 2012 08:01 PM

    We have a User Derivation Rule to assign a specific role to certain clients.  After we upgraded to 6.1.3.1 the Derivation Rule is not working.  The users are being placed in the initial role "logon" instead.  I have verified that the mac of the devices are present in the Derivation rule with the correct role.

     

    On code 3.3.3.2 it was working properly.

     

    Has anyone encountered this, is it a bug?



  • 2.  RE: ArubaOS 6.1.3.1 User derivation rule not working

    EMPLOYEE
    Posted Apr 19, 2012 10:33 PM

    Turn on user debugging to see why that user ends up in that role.

     



  • 3.  RE: ArubaOS 6.1.3.1 User derivation rule not working

    Posted Apr 19, 2012 11:47 PM

    I'll set up a test environment tomorrow.  



  • 4.  RE: ArubaOS 6.1.3.1 User derivation rule not working
    Best Answer

    Posted Jun 12, 2012 11:49 AM

    After many many tests, with the help of our Aruba onsite support, we were finally able to figure out the issue.  I had called TAC about this and they were not able to figure it out.

     

    Turns out that on the new code, at least 6.1.3.1, they have set a limit of to how many lines a derivation rule can have.  Don't know if that's by design or a flaw since it's not mentioned in the Release Notes that I can see.

     

    So, if you're having this issue, check to see how many lines your derivation rule/s have.  The max that you can have is 127.  



  • 5.  RE: ArubaOS 6.1.3.1 User derivation rule not working

    EMPLOYEE
    Posted Jul 12, 2012 01:34 PM

     

     

    These symptoms are likely covered under issues filed against S3500 and ArubaOS Mobility controller products.

     

    There are built-in limits to the total of derivation rules, so the number of rules that will work is dependent on the complete

    controller configuration.

     

    The issue was introduced in 6.1.3.0 software.

     

    Currently, engineering are working on long term fixes for the issue.

     

    In the meantime, there are  a number of possible "workarounds" which may in fact, be advantageous in larger networks.

     

    1) MAC based authentication using full, or OUI prefix, which can be used to derive.

        -  scripts are available to assist transition from the UDR configuration to the internal authentication database authentication

     

    2) Use MAC OUI prefix UDR, thereby reducing the number of UDR rules required.

    3) External authentication, using server derivation rules

     

    Aruba Networks Technical Support can provide further details regarding the issue, assisting in positively identifying if this is indeed the cause of symptoms observed,  or potential workarounds.

     

     

     

     



  • 6.  RE: ArubaOS 6.1.3.1 User derivation rule not working

    Posted Aug 01, 2012 08:00 PM

    There was nothing in the release notes in regards the issue.  TAC didn't know what the issue was either.  By testing we ended up figuring what the issue was.  We resolved the issue by just using the first 6 characters of the MAC.



  • 7.  RE: ArubaOS 6.1.3.1 User derivation rule not working

    Posted Sep 17, 2014 09:06 AM

    is this issue ever been resolved?

     

    Which code we should go to get more entries than 127?



  • 8.  RE: ArubaOS 6.1.3.1 User derivation rule not working

    Posted Sep 17, 2014 09:09 AM

    my controller is running on 6.1.3.4 and we are having same issue.

     

    we are couldn't able to add more than 127 entries. which code we can upgrade to resolove this issue

     

    Thanks in advance for any help on this matter.



  • 9.  RE: ArubaOS 6.1.3.1 User derivation rule not working

    Posted Sep 18, 2014 03:23 AM

    best bet on an answer would be TAC, they can check the bug database and advise you.



  • 10.  RE: ArubaOS 6.1.3.1 User derivation rule not working

    Posted Sep 29, 2014 11:12 AM

    Just An update...

     

    Acoording to tac its limited to 127 entries and it will be increase to 256 entries with newer code.



  • 11.  RE: ArubaOS 6.1.3.1 User derivation rule not working

    EMPLOYEE
    Posted Sep 29, 2014 11:14 AM

    Also keep in mind that UDRs were never designed to be a MAC-auth replacement. It was designed to override certain devices based on shared characteristics (MAC OUI, DHCP fingerprint, etc).