Wireless Access

last person joined: 17 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Master and Local controllers handle firewall traffic differently

This thread has been viewed 2 times
  • 1.  Master and Local controllers handle firewall traffic differently

    Posted Jan 27, 2015 04:41 PM

    We have a par of 7210s running 6.3.1.10, set as master and local.  We have user VLAN pools trunked to both controllers with no differences in switch port configuration.  There are no firewall policies applied to the interfaces, and we make use of role-based firewall policies.  The config is synced nicely between controllers. 

     

    However, a user associated with an AP on our local controller hits a phantom firewall deny rule that doesn't appear on the master controller, and doesn't show up in the config.  When we view the client status, the User Firewall State lists the denied access, but doesn't indicate what rule it's using.

     

    So strange!



  • 2.  RE: Master and Local controllers handle firewall traffic differently

    Posted Jan 27, 2015 04:48 PM

    Check under monitoring/firewall hits to see if you can decipher what role and policy is denying the action.  

    It may help if you explain what the user is trying to do when denied.

     

    You can click the "refresh now" button when you see the deny to see what "deny" actions have new hits.



  • 3.  RE: Master and Local controllers handle firewall traffic differently

    Posted Jan 27, 2015 05:00 PM

    The firewall hit does not appear in the Monitoring/firewall hits page.

     

    The user is trying to access an internal web service.



  • 4.  RE: Master and Local controllers handle firewall traffic differently
    Best Answer

    EMPLOYEE
    Posted Jan 27, 2015 04:48 PM

    Can you please do a forced configuration push?

     

    From the master:

    (config) #cfgm set sync-type complete
    (config) #write mem

     Wait about a minute or so and then change the cfgm setting back:

    (config) #cfgm set sync-type snapshot

     



  • 5.  RE: Master and Local controllers handle firewall traffic differently

    Posted Jan 27, 2015 05:04 PM

    I changed the config push setting as you suggested, and it didn't change the behaviour.



  • 6.  RE: Master and Local controllers handle firewall traffic differently

    Posted Jan 27, 2015 05:08 PM

    Here's what I see in the User Status:

     

    Source IP Source Port Destination IP Destination Port Protocol Status

    [client IP]45650[server IP]80TCPdeny


  • 7.  RE: Master and Local controllers handle firewall traffic differently

    Posted Jan 27, 2015 05:36 PM

    Can you please verify whether the destination server IP shows up in the user table on the controller?

     

    show user

    show user | include <ip-of-destination>

     

    If it does, it it a wireless client?

    If it does, what role is it in?

    If it does, run:

     

    show rights <name-of-role>



  • 8.  RE: Master and Local controllers handle firewall traffic differently

    Posted Jan 28, 2015 02:00 PM

    The destination server IP is not in the user table.  It's not a wireless client.



  • 9.  RE: Master and Local controllers handle firewall traffic differently

    Posted Jan 28, 2015 03:59 PM

    OK, today, after no further interventions, the phenomenon has disppeared.  Perhaps it just took a while for the config to sync?  Thanks to those who offered suggestions!



  • 10.  RE: Master and Local controllers handle firewall traffic differently
    Best Answer

    Posted May 01, 2015 03:24 PM

    OK, for the benefit of anyone reading this, I have discovered that the problem was misidentified.  The solution appeared to work after a delay, but it was just happenstance.   The problem cropped up again yesterday, and we were able to figure it out with the help of Aruba support.

     

    What really happened was a client joined our guest network with a static IP that was the same as the IP of our server.  There appears to be an implicit rule that denies traffic to an invalid wireless client IP.  The problem is, as long as the client exists in the controller, that IP is blocked.  If you kick the client off, the server is suddenly accessible again. 

     

    Anyone else experience something like this?  Any thoughts about how to fix this other than kicking that client off (or blacklisting it)? 



  • 11.  RE: Master and Local controllers handle firewall traffic differently
    Best Answer

    EMPLOYEE
    Posted May 01, 2015 03:26 PM
    Did TAC tell you about the validuser acl?


  • 12.  RE: Master and Local controllers handle firewall traffic differently

    Posted May 01, 2015 03:49 PM

    No, they didn't.

     

    I'm just reviewing the configuration for this (good youtube video: https://www.youtube.com/watch?v=HMIQwok5r1o)

     

    Thanks for reminding me about that!  I think this is the real solution.